CVE-2026-93533
A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::ch
CVSS
6.3
Medium
EPSS
1.1%
p65
KEV
—
Exploit Today
19
0-100
Published: Sep 18, 2026 · Last modified: Sep 18, 2026 · CWE-77 · CWE-78
Not enough EPSS history yet.
A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. This manipulation of the argument host causes os command injection. It is possible to initiate the attack remotely. The pull request to fix this issue awaits acceptance.
- github.comhttps://github.com/spatie/scotty/
- github.comhttps://github.com/spatie/scotty/issues/20
- github.comhttps://github.com/spatie/scotty/pull/22
- vuldb.comhttps://vuldb.com/cve/CVE-2026-93533
- vuldb.comhttps://vuldb.com/submit/943917
- vuldb.comhttps://vuldb.com/vuln/407450
- vuldb.comhttps://vuldb.com/vuln/407450/cti
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-937429.9 CRI78.5%
——24A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.20hCVE-2026-840858.1 HIG24.9%
——7IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.14hCVE-2026-840717.2 HIG72.2%
——22IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.1dCVE-2026-828928.1 HIG32.4%
——10IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.13hCVE-2026-828878.8 HIG34.9%
——10IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.13hCVE-2026-819377.2 HIG72.2%
——22IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potentially resulting in arbitrary command execution with root privileges and impact to the confidentiality, integrity, and availability of the affected system.1d