CVE-2026-59111
moderateOS Command Injection in DIA eObčanka-Identifikace for macOS
CVE-2026-59111 is an OS command injection (CWE-78) flaw in the Digitální a informační agentura (DIA) eObčanka-Identifikace application on macOS, which handles Czech electronic identity (eObčanka) authentication. The app registers the custom URL scheme czeeopauth:// to launch parameterized application execution, and before version 3.6.0 incoming URL parameters were passed to a compiled AppleScript wrapper via concatenation without sufficient sanitization. An attacker can exploit this by getting a user to open a crafted czeeopauth:// link (e.g., from a web page or email), injecting OS commands that execute in the context of the application — the scope-changed CVSS vector (S:C with high confidentiality and integrity impact) reflects the attack crossing a trust boundary via the URL scheme. Users of eObčanka-Identifikace on macOS running any version prior to 3.6.0 are affected. There is no evidence of exploitation in the wild: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only about a 0.8% chance of exploitation within 30 days.
What to do: Upgrade eObčanka-Identifikace on macOS to version 3.6.0 or later, which sanitizes URL scheme parameters. As an interim mitigation, avoid opening czeeopauth:// links from untrusted sources and verify the installed version of the app on managed Macs.
| Digitální a informační agentura (DIA) eObčanka-Identifikace (macOS) | all versions prior to 3.6.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for parameterized application execution. Prior to version 3.6.0, incoming URL parameters were passed to the compiled AppleScript wrapper using concatenation without sufficient sanitization.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.