CVE-2026-3065
PoC nicheCommand Injection in HummerRisk Cloud Task Dry-run (up to 1.5.0)
CVE-2026-3065 is a command injection flaw (CWE-74/CWE-77) in the CommandUtils.commonExecCmdWithResult function of CloudTaskService.java, part of HummerRisk's Cloud Task Dry-run component. A remote, low-privileged authenticated user (PR:L per the CVSS vector) can trigger it by supplying a crafted fileName argument that is passed into an executed command. Successful exploitation allows arbitrary command execution on the host running HummerRisk, although the CVSS 4.0 score rates the confidentiality, integrity and availability impact as limited (overall 2.1, low). All HummerRisk deployments up to and including version 1.5.0 are affected, and the vendor was contacted about the disclosure but did not respond. A public proof-of-concept exploit is already available, and the 30.5% EPSS (98th percentile) points to a high likelihood of exploitation within 30 days, though the flaw is not yet in CISA KEV and no confirmed in-the-wild exploitation is documented.
What to do: Upgrade beyond 1.5.0 as soon as a patched release is published on the project's official repository, since the vendor did not respond to the disclosure and no fixed version is confirmed. In the meantime, restrict which accounts can reach the Cloud Task Dry-run feature, ensure the fileName input is validated or sanitized before being passed to command execution, and monitor HummerRisk hosts for suspicious command activity given the public PoC and high EPSS.
| hummerrisk | All versions up to and including 1.5.0 (no patched version confirmed in the disclosure; vendor did not respond) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was detected in HummerRisk up to 1.5.0. This affects the function CommandUtils.commonExecCmdWithResult of the file CloudTaskService.java of the component Cloud Task Dry-run. Performing a manipulation of the argument fileName results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- hummerrisk
- Products
- hummerrisk
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.