Cyber Resilience

CVE-2024-26260

CriticalRCE

Published: 15 February 2024

Published
15 February 2024
Modified
23 January 2025
KEV Added
Patch
CVSS Score v3.1 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0275 86.3th percentile
Risk Priority 21 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2024-26260 is a critical-severity OS Command Injection (CWE-78) vulnerability in Hgiga Oaklouds-Organization-2.0. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 13.7% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without permission.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

hgiga
oaklouds-organization-2.0
≤ 188
hgiga
oaklouds-organization-3.0
≤ 188
hgiga
oaklouds-webbase-2.0
≤ 1051
hgiga
oaklouds-webbase-3.0
≤ 1051

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-78

Platform-independent apps typically execute inside a managed runtime or sandbox that restricts direct OS command execution, reducing the ability to exploit OS command injection.

addresses: CWE-78

Validates inputs to block special elements that would alter OS command execution.

References