What is CVE-2026-64878?
CVE-2026-64878 allows shell metacharacters to escape command argument handling via unvalidated input in asset filter parameters through the Analysis REST endpoint, leading to remote code execution as a low-privileged OS user. Affected systems should enforce strict input validation on REST endpoint parameters.
Azərbaycanca: CVE-2026-64878 Analysis REST endpoint vasitəsilə asset filter parametrlərində yoxlanılmamış giriş nəticəsində shell metacharacter-lərin əmr arqumentlərindən qaçmasına səbəb olur. Bu, az imtiyazlı əməliyyat sistemi istifadəçisi kimi uzaqdan kod icrasına yol açır. Təsirə məruz qalan sistemlərdə istifadəçi girişlərinin ciddi yoxlanması tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-78
FAQ1
Which REST endpoint is used to exploit CVE-2026-64878?
The vulnerability is exploited through the Analysis REST endpoint via unvalidated input in asset filter parameters.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.