← Back

CVE-2026-33613

nvd nist
Published: Apr 2, 2026Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpArray function, resulting in full system compromise. This vulnerability can only be attacked if the attacker has some other way to write arbitrary data to the user table.

Affected (2)

2 products
Mbconnect24
Mymbconnect24
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.19.4
Up to 2.19.4

References (2)

Timeline

No history available yet.