What is CVE-2026-66902?
This vulnerability in Google::Auth Perl module versions before 0.06 allows execution of an external command from external_account credentials via an unsanitized system call. It impacts systems using the Pluggable subclass, which reads credential_source.executable.command from the credentials JSON and passes it directly to `system()`, enabling arbitrary code execution. Immediate upgrade to the latest version is recommended.
Azərbaycanca: Bu zəiflik Google::Auth Perl modulunun 0.06-dan əvvəlki versiyalarında `external_account` etimadnaməsindəki xarici əmri sistem çağırışı vasitəsilə işlətməsinə imkan verir. Təsirə məruz qalan sistemlərdə `credentials_source.executable.command` dəyəri yoxlanılmadığı üçün ixtiyari kod icrası mümkündür. Modulu dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which Perl module is affected by CVE-2026-66902?
This vulnerability affects Google::Auth Perl module versions prior to 0.06.
How to protect against CVE-2026-66902?
It is recommended to immediately upgrade the Google::Auth Perl module to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.