« Volver al listado

CVE-2026-11408

Estado: AplazadaBaja (2.1)—

A vulnerability was identified in vertex-app vertex up to 2026.02.12. This issue affects some unknown processing of the file app/model/LogMod.js of the component Log Viewer Endpoint. Such manipulation of the argument req.query leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The name of the patch is 805d82e7100d49b79b3beb1b9420e8e458987198. It is best practice to apply a patch to resolve this issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-11408",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-11408",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-08T14:20:07.651513Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Secondary",
        "source": "cna@vuldb.com",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@vuldb.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "cna@vuldb.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 2.1,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "PROOF_OF_CONCEPT",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "cna@vuldb.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:vertex-app:vertex:*:*:*:*:*:*:*:*"
          ],
          "vendor": "vertex-app",
          "modules": [
            "Log Viewer Endpoint"
          ],
          "product": "vertex",
          "versions": [
            {
              "status": "affected",
              "version": "2026.02.0"
            },
            {
              "status": "affected",
              "version": "2026.02.1"
            },
            {
              "status": "affected",
              "version": "2026.02.2"
            },
            {
              "status": "affected",
              "version": "2026.02.3"
            },
            {
              "status": "affected",
              "version": "2026.02.4"
            },
            {
              "status": "affected",
              "version": "2026.02.5"
            },
            {
              "status": "affected",
              "version": "2026.02.6"
            },
            {
              "status": "affected",
              "version": "2026.02.7"
            },
            {
              "status": "affected",
              "version": "2026.02.8"
            },
            {
              "status": "affected",
              "version": "2026.02.9"
            },
            {
              "status": "affected",
              "version": "2026.02.10"
            },
            {
              "status": "affected",
              "version": "2026.02.11"
            },
            {
              "status": "affected",
              "version": "2026.02.12"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-06T11:16:48.347",
  "references": [
    {
      "url": "https://drive.google.com/drive/folders/1DO-kB1eUoB1CksJ_ZKzpUaX0kp5Rgm_T?usp=sharing",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://gist.github.com/menelausx/e632faba4014474fcef6a1f541ca3e4e",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://github.com/vertex-app/vertex/",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://github.com/vertex-app/vertex/commit/805d82e7100d49b79b3beb1b9420e8e458987198",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/cve/CVE-2026-11408",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/submit/818442",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/vuln/368967",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/vuln/368967/cti",
      "source": "cna@vuldb.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@vuldb.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-77"
        },
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability was identified in vertex-app vertex up to 2026.02.12. This issue affects some unknown processing of the file app/model/LogMod.js of the component Log Viewer Endpoint. Such manipulation of the argument req.query leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The name of the patch is 805d82e7100d49b79b3beb1b9420e8e458987198. It is best practice to apply a patch to resolve this issue."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad fue identificada en vertex-app vertex hasta 2026.02.12. Este problema afecta a algún procesamiento desconocido del archivo app/model/LogMod.js del componente Log Viewer Endpoint. Tal manipulación del argumento req.query lleva a inyección de comandos. El ataque puede ser ejecutado remotamente. El exploit está disponible públicamente y podría ser usado. El nombre del parche es 805d82e7100d49b79b3beb1b9420e8e458987198. Es una buena práctica aplicar un parche para resolver este problema."
    }
  ],
  "lastModified": "2026-07-23T07:10:00.113",
  "sourceIdentifier": "cna@vuldb.com"
}