Sceawere
Vulnerability Detail
CVE-2026-96349UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Remote Code Execution
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 3h ago
- Vendor
- SiteSkite
- Product
- SiteSkite
- Attack Type
- CWE-94 Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-09-30T13:17:29.967Z",
"pubdate": "2026-09-30T13:17:29.967Z",
"executiveSummary": "This vulnerability is an Unauthenticated Remote Code Execution (RCE) flaw affecting SiteSkite versions 2.1.8 and earlier. The vulnerability allows an unauthenticated remote attacker to execute arbitrary code on the underlying host operating system by sending a maliciously crafted request to the application.\nThe flaw stems from improper input validation or insecure handling of user-supplied data, which facilitates direct command injection or file-based code execution. Successful exploitation results in complete system compromise, enabling the attacker to gain full administrative control over the affected server, access sensitive application data, or deploy persistent backdoors.\nGiven that the vulnerability does not require authentication, it is highly critical and poses a significant risk to the availability, integrity, and confidentiality of the targeted system. Exploitation can be performed remotely over the network with minimal effort, making this a high-priority threat for organizations utilizing SiteSkite 2.1.8 or earlier. Mitigation necessitates immediate action, including the identification of affected deployments and the application of vendor-supplied patches or restrictive network controls to prevent unauthorized access.",
"technicalDetails": "The vulnerability is identified as a Remote Code Execution (RCE) flaw residing within SiteSkite versions <= 2.1.8. The root cause pertains to insufficient neutralization of user-controlled input, which is subsequently passed to a system-level execution function or processed by the application's interpreter without adequate sanitization or boundary checks.\nThe exploitation process typically follows a defined attack flow: First, the attacker identifies an exposed endpoint within the SiteSkite application that accepts user input, such as a URL parameter, HTTP header, or form field. The attacker crafts a malicious payload—often leveraging shell metacharacters (e.g., semicolon, pipe, backticks) or serialized objects—designed to execute operating system commands under the context of the web server process (e.g., www-data or system).\nOnce the payload is transmitted to the server via an HTTP request, the vulnerable component parses the malicious input. If the application directly passes this unsanitized data into functions such as 'system()', 'exec()', or 'passthru()', the server executes the injected command immediately. In scenarios involving file upload vulnerabilities or insecure deserialization, the attacker may upload a web shell (e.g., a PHP or JSP script) into a directory accessible via the web root. Once uploaded, the attacker invokes the web shell via a direct HTTP GET request to the file path, thereby achieving persistent execution capabilities.\nThe network exposure is global, as the vulnerability does not require prior authentication or elevated privileges. Because the application processes the input before verifying the requester's identity, an external attacker can exploit this flaw from any network segment that has connectivity to the application's port.\nPost-exploitation impact is severe. Upon successful command execution, the attacker can traverse the file system, exfiltrate sensitive configuration files (e.g., database credentials, environment variables), or establish a reverse shell to facilitate long-term persistence within the host environment. Furthermore, the attacker may leverage the compromised server as a pivot point to conduct lateral movement within the internal network infrastructure. Because the execution occurs in the context of the application user, any restrictions placed on the web server service account are the only barriers to total system takeover."
}