Critical Alert 2 Active Exploits Detected Today

CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability →
CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability →
Powered by CVE Watchtower
×
September 1, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-56415NVD

Vulnerability Summary

Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is processed without adequate input sanitization, resulting in arbitrary command execution with root-level privileges on the underlying system.
Severity Level
CRITICAL(10.0)
Published Date
Jun 30, 2026
Last Modified
Jul 1, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
3.15%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh