CVE-2026-8153 PUBLISHED

Command injection in Dashboard Server interface

Assigner: TRO
Reserved: 08.05.2026 Published: 08.05.2026 Updated: 08.05.2026

OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.21.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Universal Robots
Product PolyScope 5
Versions Default: unaffected
  • affected from 0 to 5.25.1 (excl.)

Affected Configurations

Only applicable if Dashboard Server interface is active

Solutions

Update to version 5.21.1 or later, or disable Dashboard Server interface

Credits

  • Vera Mens of Claroty Team82 finder

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE

Impacts

  • CAPEC-88 OS Command Injection