What is CVE-2026-49481?
CVE-2026-49481 is an OS command injection vulnerability in UpSnap, a wake on LAN web app, affecting versions prior to 5.4.0. The flaw exists in the device management functionality due to unsafe shell command template interpolation using the ip and mac fields, allowing user-controlled values to execute arbitrary system commands. Users must upgrade to version 5.4.0 or later immediately.
Azərbaycanca: CVE-2026-49481, UpSnap (wake on LAN veb tətbiqi) 5.4.0-dan əvvəlki versiyalarda device management funksiyasında aşkarlanmış OS command injection zəifliyidir. İp və mac sahələrindəki təhlükəli shell command template interpolation səbəbindən istifadəçi tərəfindən idarə olunan dəyərlər sistem əmrlərinin icrasına səbəb ola bilər. UpSnap istifadəçiləri dərhal 5.4.0 və ya daha yeni versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
In which functionality of UpSnap does CVE-2026-49481 exist?
The vulnerability exists in the device management functionality of UpSnap.
To which version should users upgrade to protect against CVE-2026-49481?
UpSnap users should upgrade to version 5.4.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.