What is CVE-2026-66148?
An authenticated command injection vulnerability was found in GMS Command-Line Interface (CLI) 9.5.1 and earlier. This allows a low-privileged local user to execute system commands with root privileges. Updating the CLI application to the latest version on affected systems is recommended.
Azərbaycanca: GMS Command-Line Interface (CLI) 9.5.1 və daha əvvəlki versiyalarda autentifikasiya olunmuş komanda inyeksiya zəifliyi aşkar edilib. Bu zəiflik aşağı imtiyazlı lokal istifadəçiyə root hüquqları ilə sistem komandalarını icra etməyə imkan verir. Təsirə məruz qalan sistemlərdə CLI tətbiqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Does exploiting CVE-2026-66148 in GMS CLI require authentication?
Yes, it is an authenticated command injection vulnerability, meaning the attacker must log in to the system as a local low-privileged user.
What should be done to mitigate CVE-2026-66148?
It is recommended to update the GMS CLI application to the latest version on affected systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.