← Terug naar overzicht

An OS command injection vulnerability (CVE-2026-57499) was discovered in Liman, an open source server management software. The flaw exists in the log rotation configuration endpoint and affects versions prior to 2.2.2 - 1103. An authenticated administrator can exploit the vulnerability by injecting shell commands through the unsanitized 'ip_address' parameter via single-quote injection. This allows arbitrary operating system command execution on the Liman server. The vulnerability has been patched in version 2.2.2 - 1103. Although exploitation requires administrator authentication, it represents a significant privilege escalation and lateral movement risk. Users are advised to upgrade immediately to the fixed version.

Affected products

  • Liman

Related CVE's

  • CVE-2026-57499

Categories

  • Enterprise Applications
  • Web Technologies