What is CVE-2026-73615?
CVE-2026-73615: This vulnerability in Network-AI versions before 5.15.1 allows a security matcher bypass due to inconsistent command parsing. SandboxPolicy evaluates raw commands with quotes intact, while the executor strips quotes before execution, enabling attackers to craft commands that evade blocklist checks. Updating to version 5.15.1 or later is recommended.
Azərbaycanca: CVE-2026-73615: Bu zəiflik Network-AI platformasının 5.15.1-dən əvvəlki versiyalarında təhlükəsizlik filtrinin yan keçməsinə imkan verir. Səbəb odur ki, SandboxPolicy xam əmrləri dırnaq işarələrini qoruyaraq yoxlayır, executor isə icradan əvvəl dırnaqları silərək fərqli tokenizasiya aparır. Nəticədə, təcavüzkarlar blok siyahıdan yayınan saxta əmrlər yarada bilər. Platformanı 5.15.1 və ya daha yaxşı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
How is CVE-2026-73615 exploited?
Attackers craft commands that evade blocklist checks by exploiting the inconsistency where SandboxPolicy evaluates raw commands with quotes intact, but the executor strips them before execution.
Which versions of Network-AI are affected by CVE-2026-73615?
Versions before 5.15.1 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.