CVE-2026-22103
Command injection in NPC start web endpoint
| CVE | CVE-2026-22103 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Title | Command injection in NPC start web endpoint | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Credits |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Affected products |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| CVSS |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| References |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Problem type(s) | CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Date published | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Last modified | 16 Jul 2026 15:41 UTC | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.
JSON version.