What is CVE-2026-71235?
CVE-2026-71235 is a critical vulnerability in Magistrala's Rules Engine, allowing authenticated users to execute server-side Go/Lua scripts with unrestricted OS access via the Yaegi interpreter. This affects Magistrala IoT deployments, and users must immediately disable the rules engine or apply vendor patches to prevent remote code execution.
Azərbaycanca: CVE-2026-71235, Magistrala platformasının Rules Engine komponentində aşkar edilmiş kritik boşluqdur. Autentifikasiyadan keçmiş istifadəçilər IoT mesajları emal edilərkən server tərəfdə işə düşən Go/Lua skriptlər vasitəsilə əməliyyat sistemi əmrlərini icra edə bilər. Magistrala istifadəçiləri dərhal platformanı müvəqqəti söndürməli və təchizatçının yamaq təlimatlarını izləməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which Magistrala component is affected by the unrestricted OS command risk in CVE-2026-71235?
CVE-2026-71235 affects the Rules Engine component of the Magistrala platform, where authenticated users can execute OS commands via Go/Lua scripts through the Yaegi interpreter.
What immediate action should Magistrala users take to address CVE-2026-71235?
Magistrala users must immediately disable the platform or turn off the Rules Engine, and follow the vendor's patch instructions to prevent remote code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.