The 
iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

Project Subscriptions

Vendors Products
Isherlock-audit Subscribe
Isherlock-base Subscribe
Advisories

No advisories yet.

Fixes

Solution

Update iSherlock-base-4.5 package to version 476 or later Update iSherlock-audit-4.5 package to version 261 or later Update iSherlock-base-5.5 package to version 476 or later Update iSherlock-audit-5.5 package to version 261 or later


Workaround

No workaround given by the vendor.

History

Thu, 16 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Apr 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Hgiga
Hgiga isherlock-audit
Hgiga isherlock-base
Vendors & Products Hgiga
Hgiga isherlock-audit
Hgiga isherlock-base

Thu, 16 Apr 2026 02:45:00 +0000

Type Values Removed Values Added
Description The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
Title HGiga|iSherlock - OS Command Injection
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-04-16T13:43:07.281Z

Reserved: 2026-04-15T11:32:29.759Z

Link: CVE-2026-6349

cve-icon Vulnrichment

Updated: 2026-04-16T13:43:02.940Z

cve-icon NVD

Status : Received

Published: 2026-04-16T03:16:30.660

Modified: 2026-04-16T03:16:30.660

Link: CVE-2026-6349

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T09:15:30Z

Weaknesses