CVE-2026-71376: OS Command Injection Vulnerability in Cosminexus Component Container
OS command injection vulnerability in Cosminexus Component Container.
This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require authentication or user interaction?
The CVSS vector indicates exploitation can be performed remotely over the network with low attack complexity, without privileges or user interaction. Successful exploitation can affect confidentiality, integrity, and availability.
Which releases need to be remediated?
Affected releases include 11-70-01 before 11-70-03; 11-60 before 11-60-03; 11-50 through 11-50-03; 11-40 through 11-40-03; 11-30 through 11-30-08; 11-20 before 11-20-10; 11-10 through 11-10-11; 11-00 before 11-00-13; 09-87 before 09-87-10; 09-80 before 09-80-05; 09-70 before 09-70-28; 09-50 through 09-50-22; and 09-00 through 09-00-18. Compare the installed Component Container release with these ranges to determine exposure.