Cyber Posture

CVE-2026-1413

Medium

Published: 26 January 2026

Published
26 January 2026
Modified
30 January 2026
KEV Added
Patch
CVSS Score 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score 0.0006 17.2th percentile
Risk Priority 13 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-1413 is a medium-severity Injection (CWE-74) vulnerability in Sangfor Operation And Maintenance Security Management System. Its CVSS base score is 6.3 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 17.2th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploit Public-Facing Application (T1190) and 1 other technique.
Threat & Defense Details

Likely Mitigating ControlsAI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-74

Developer assessments and testing (including injection-focused techniques) identify improper neutralization of special elements, and the verifiable flaw remediation corrects them pre-deployment.

addresses: CWE-74

Identifies indicators of injection attacks (command, SQL, LDAP, etc.) via anomaly and attack monitoring.

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1059.004 Unix Shell Execution
Adversaries may abuse Unix shell commands and scripts for execution.
Why these techniques?

Command injection in remotely accessible web management system directly enables remote code execution via Unix shell.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

A vulnerability was found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function portValidate of the file /fort/ip_and_port/port_validate of the component HTTP POST Request Handler. Performing a manipulation of the argument port results in…

more

command injection. The attack can be initiated remotely. The exploit has been made public and could be used.

Deeper analysisAI

CVE-2026-1413 is a command injection vulnerability affecting the Sangfor Operation and Maintenance Security Management System up to version 3.0.12. The issue resides in the portValidate function within the file /fort/ip_and_port/port_validate of the HTTP POST Request Handler component. Manipulation of the 'port' argument enables arbitrary command execution, classified under CWE-74 and CWE-77.

The vulnerability allows remote exploitation by attackers with low privileges (PR:L), low attack complexity (AC:L), and no user interaction (UI:N). Successful attacks result in low impacts to confidentiality, integrity, and availability (C:L/I:L/A:L), yielding a CVSS 3.1 base score of 6.3. An exploit for this vulnerability has been made public.

Advisories and additional details are available in references including the GitHub issue at https://github.com/LX-LX88/cve/issues/23 and VulDB entries at https://vuldb.com/?ctiid.342802, https://vuldb.com/?id.342802, and https://vuldb.com/?submit.736522. The CVE was published on 2026-01-26.

Details

CWE(s)

Affected Products

sangfor
operation and maintenance security management system
≤ 3.0.12

CVEs Like This One

CVE-2025-12916Same product: Sangfor Operation And Maintenance Security Management System
CVE-2026-1412Same product: Sangfor Operation And Maintenance Security Management System
CVE-2025-15502Same product: Sangfor Operation And Maintenance Security Management System
CVE-2026-1414Same product: Sangfor Operation And Maintenance Security Management System
CVE-2025-15501Same product: Sangfor Operation And Maintenance Security Management System
CVE-2026-1325Same product: Sangfor Operation And Maintenance Security Management System
CVE-2026-1324Same product: Sangfor Operation And Maintenance Security Management System
CVE-2025-15503Same product: Sangfor Operation And Maintenance Security Management System
CVE-2025-15499Same vendor: Sangfor
CVE-2025-15500Same vendor: Sangfor

References