What is CVE-2026-50772?
CVE-2026-50772 is a remote code execution (RCE) vulnerability in Squirro Cognitive Search versions prior to 3.14.2, triggered via a crafted payload in the password reset function. Affected users should immediately update Squirro to the latest version to mitigate the risk.
Azərbaycanca: CVE-2026-50772: Squirro Cognitive Search-in 3.14.2-dən əvvəlki versiyalarında parol sıfırlama funksiyasına xüsusi hazırlanmış payload göndərərək remote code execution (RCE) zəifliyidir. Təsirə məruz qalan sistemlər üçün dərhal Squirro-nu son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which functionality does an attacker need to target to exploit CVE-2026-50772?
The attacker must send a crafted payload to the password reset function.
To which version should Squirro be updated to protect against CVE-2026-50772?
It is recommended to update Squirro to version 3.14.2 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.