CVE-2026-2339 PUBLISHED

RCE in TUBITAK BILGEM's Liderahenk

Assigner: TR-CERT
Reserved: 11.02.2026 Published: 10.03.2026 Updated: 10.03.2026

Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code Inclusion, Privilege Abuse, Command Injection.This issue affects Liderahenk: before v3.4.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 7.5

Product Status

Vendor TUBITAK BILGEM Software Technologies Research Institute
Product Liderahenk
Versions Default: unaffected
  • affected from 0 to v3.4.0 (excl.)

Credits

  • Edip ALHAZOURİ finder

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE

Impacts

  • CAPEC-253 Remote Code Inclusion
  • CAPEC-122 Privilege Abuse
  • CAPEC-248 Command Injection