Sceawere
Vulnerability Detail
CVE-2026-71376UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OS Command Injection in Cosminexus
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 3h ago
- Vendor
- Hitachi
- Product
- Cosminexus Component Container
- Attack Type
- CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-09-08T09:18:20.713Z",
"pubdate": "2026-09-08T09:18:20.713Z",
"executiveSummary": "An OS command injection vulnerability exists within the Cosminexus Component Container, allowing remote unauthenticated attackers to execute arbitrary commands on the underlying host operating system.\nThe vulnerability stems from improper input validation when processing specific requests, leading to the potential for unauthorized code execution with the privileges of the application process.\nThis issue impacts a wide array of versions ranging from 09-00 to 11-70-02.\nSuccessful exploitation allows for complete system compromise, data exfiltration, and the modification of sensitive configuration files.\nRisk implications are critical due to the potential for full administrative control over the application server environment.\nNo specific preconditions beyond network reachability to the vulnerable component are required for exploitation.",
"technicalDetails": "The vulnerability is characterized as an OS command injection flaw, where the Cosminexus Component Container fails to properly sanitize user-supplied input before passing it to system-level calls or shell interpreters.\nThis flaw allows an attacker to inject shell metacharacters into the application's processing logic, effectively chaining commands that are then executed by the system shell.\nThe attack flow typically involves sending a crafted HTTP request containing malicious command sequences targeting a vulnerable interface or administrative component within the container. When the application processes this input, it fails to differentiate between legitimate configuration parameters and injected command strings, leading to the execution of the attacker's payload.\nThe vulnerable component is intrinsic to the core request handling functionality of the Cosminexus Component Container. Because the application often runs with elevated service account privileges, the executed commands inherit those permissions, potentially granting the attacker persistence, lateral movement capabilities, and access to internal databases or file systems.\nAffected versions include: 11-70-01 before 11-70-03, 11-60 before 11-60-03, 11-50 through 11-50-03, 11-40 through 11-40-03, 11-30 through 11-30-08, 11-20 before 11-20-10, 11-10 through 11-10-11, 11-00 before 11-00-13, 09-87 before 09-87-10, 09-80 before 09-80-05, 09-70 before 09-70-28, 09-50 through 09-50-22, and 09-00 through 09-00-18.\nPost-exploitation impact includes unauthorized reading and manipulation of application data, installation of backdoors or remote access trojans (RATs), and potential escalation of privileges depending on the host's hardening configuration. The vulnerability exposes the underlying infrastructure to arbitrary system-level activity that bypasses standard application-layer security controls."
}