What is CVE-2026-73226?
A vulnerability in electerm allows an authenticated WebSocket client to invoke unintended internal functions via uncontrolled `func` values in `dispatch-center.js`. Users should upgrade to version 3.15.186 or later.
Azərbaycanca: electerm terminal/SSH/SFTP müştərisində autentifikasiya olunmuş WebSocket istifadəçisinə server daxilində nəzərdə tutulmayan funksiyaları çağırmağa imkan verən boşluq aşkarlanıb. Bu, `dispatch-center.js` faylındakı `func` parametrinin düzgün yoxlanılmaması səbəbindən baş verir. İstifadəçilər 3.15.186 versiyasına yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Is authentication required to exploit CVE-2026-73226?
Yes, the attacker must be an authenticated user via WebSocket connection.
Which component of electerm contains the CVE-2026-73226 vulnerability?
The vulnerability is in the `dispatch-center.js` file due to insufficient validation of the `func` parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.