CVE-2026-85523EPSS p58.7%
CVE-2026-85523CVE-2026-85523
Description
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Felisify Information Technologies Industry and Trade Inc. SambaBox allows OS Command Injection.
This issue affects SambaBox: before 5.4.1.
Scoring
| CVSS | 8.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.91% probability of exploitation · percentile 58.7% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-06 |