CVE-2026-85523 PUBLISHED

OS Command Injection in Felisify Informatics' SambaBox

Assigner: TR-CERT
Reserved: 04.09.2026 Published: 06.10.2026 Updated: 06.10.2026

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Felisify Information Technologies Industry and Trade Inc. SambaBox allows OS Command Injection.

This issue affects SambaBox: before 5.4.1.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor Felisify Information Technologies Industry and Trade Inc.
Product SambaBox
Versions Default: unaffected
  • affected from 0 to 5.4.1 (excl.)

Credits

  • Eyyüb Ensar Demir finder

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE

Impacts

  • CAPEC-88 OS Command Injection