CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
3,673 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-42271 — LiteLLM: Authenticated command execution via MCP stdio test endpoints
- CVE-2026-39808 — A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
- CVE-2026-1731 — Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
- CVE-2025-64328 — FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
- CVE-2025-1316 — Edimax IC-7100 IP Camera OS Command Injection
- CVE-2024-9463 — Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
- CVE-2024-4577 — Argument Injection in PHP-CGI
- CVE-2024-23108 — An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
- CVE-2025-34073 — stamparm/maltrail <=0.54 Remote Command Execution
- CVE-2024-9474 — PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
- CVE-2024-12987 — DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
- CVE-2025-25256 — An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
- CVE-2025-34037 — Linksys Routers E/WAG/WAP/WES/WET/WRT-Series
- CVE-2026-10520 — An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
- CVE-2024-24576 — Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
- CVE-2024-47407 — mySCADA myPRO OS Command Injection
- CVE-2024-10443 — Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager
- CVE-2024-12847 — NETGEAR DGN setup.cgi OS Command Injection
- CVE-2025-54123 — Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
- CVE-2026-25089 — A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
Recently published
- CVE-2026-79689 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79641 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-87088 — Tanium addressed an unauthorized code execution vulnerability in Enforce.
- CVE-2026-78630 — Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing
- CVE-2026-82004 — Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
- CVE-2026-86733 — Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore
- CVE-2026-61517 — Netis NX10 OS Command Injection via Ping Diagnostic Handler
- CVE-2026-71376 — OS Command Injection Vulnerability in Cosminexus Component Container
- CVE-2026-76561 — Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile content (externalprocessconstraint)
- CVE-2026-86540 — knowns before 0.30.0 Arbitrary Code Execution via LSP Binary
- CVE-2026-80127 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-78488 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-19843 — 389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor
- CVE-2026-61409 — Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of
- CVE-2026-86299 — Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection
- CVE-2026-84256 — An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authe
- CVE-2026-86167 — Tenda HG10 Boa formgponConf os command injection
- CVE-2026-86152 — Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection
- CVE-2026-86151 — Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection
- CVE-2026-86149 — Tenda CP3 NetCheckPing.cpp os command injection