What is CVE-2026-16630?
An OS command injection vulnerability was found in Syncfusion ej2-javascript-ui-controls up to version 33.2.3, affecting the 'child_process.exec' function in the 'package.json' file. This flaw requires local access for exploitation and has a publicly disclosed exploit. Users should update to the latest patched version immediately to mitigate the risk.
Azərbaycanca: Syncfusion ej2-javascript-ui-controls kitabxanasında 33.2.3 versiyasına qədər olan versiyalarda OS command injection zəifliyi aşkar edilib. Bu, 'package.json' faylındakı 'child_process.exec' funksiyasının manipulyasiyası nəticəsində baş verir və lokal giriş tələb edir. Təhlükəsizlik mütəxəssisləri dərhal kitabxananı ən son versiyaya yeniləməli və lokal giriş icazələrini nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which component is affected by CVE-2026-16630 in the Syncfusion ej2-javascript-ui-controls library?
The vulnerability affects the 'child_process.exec' function within the 'package.json' file.
What level of access is required to exploit CVE-2026-16630?
Exploitation of this vulnerability requires local access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.