CVE-2026-90843: SabyasachiRana WebMap New Nmap Scan functions_nmap.py nmap_newscan os command injection

Published Sep 15, 2026
·
Updated

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmapnewscan of the file functionsnmap.py of the component New Nmap Scan Handler. Such manipulation of the argument target/params leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 3d52f65803a2716bff14d938352c6fef45b0cfb6. A patch should be applied to remediate this issue. This issue got fixed with a silent patch.

Affected Software

1 affected component
SabyasachiRana WebMap<=8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SabyasachiRana WebMap (New Nmap Scan Handler) to a version that resolves this vulnerability.

    Patch 3d52f65803a2716bff14d938352c6fef45b0cfb6
  2. Compensating control

    Because the nmap_newscan function in functions_nmap.py (New Nmap Scan Handler) is vulnerable to remote os command injection via manipulation of the target/params argument, restrict network/firewall access to the WebMap component and its Nmap scan functionality to trusted sources only until the silent patch is applied.

Event History

Sep 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker can launch the attack remotely and does not need privileges or user interaction, according to the supplied severity vector. Exploitation targets the New Nmap Scan Handler's target or params arguments.

2

Are publicly available exploits a concern?

Yes. The exploit has been publicly disclosed and may be used, so exposed instances should be treated as at increased risk.

3

What remediation is identified?

Apply patch 3d52f65803a2716bff14d938352c6fef45b0cfb6. The issue was fixed through a silent patch.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203