CVE-2026-3120 PUBLISHED

RCE in Profelis Informatics' SambaBox

Assigner: TR-CERT
Reserved: 24.02.2026 Published: 04.05.2026 Updated: 04.05.2026

Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection.

This issue affects SambaBox: from 5.1 before 5.3.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.2

Product Status

Vendor Profelis Information and Consulting Trade and Industry Limited Company
Product SambaBox
Versions Default: unaffected
  • affected from 5.1 to 5.3 (excl.)

Credits

  • Kayra BÜYÜKLÜ finder

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE

Impacts

  • CAPEC-88 OS Command Injection