CVE-2026-59111 PUBLISHED

Command Injection vulnerability in eObčanka-Identifikace

Assigner: ENISA
Reserved: 02.07.2026 Published: 31.08.2026 Updated: 31.08.2026

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for parameterized application execution. Prior to version 3.6.0, incoming URL parameters were passed to the compiled AppleScript wrapper using concatenation without sufficient sanitization.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
CVSS Score: 9.3

Product Status

Vendor Ministry of the Interior (MVČR)
Product eObčanka-Identifikace
Versions Default: unaffected
  • affected from 0 to 3.5.1 (incl.)

Solutions

remediated in v3.6.0 (Released: 2026-05-13) - Implemented AppleScript sanitization fixed in v3.7.0 (Released: 2026-07-17) - AppleScript was completely removed from the bundle

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE