ZeroHour

CVE-2026-59111

moderate

OS Command Injection in DIA eObčanka-Identifikace for macOS

CVSS 3.1
9.3 critical
EPSS
<1%p54
Published
()
Modified
AI analysis

CVE-2026-59111 is an OS command injection (CWE-78) flaw in the Digitální a informační agentura (DIA) eObčanka-Identifikace application on macOS, which handles Czech electronic identity (eObčanka) authentication. The app registers the custom URL scheme czeeopauth:// to launch parameterized application execution, and before version 3.6.0 incoming URL parameters were passed to a compiled AppleScript wrapper via concatenation without sufficient sanitization. An attacker can exploit this by getting a user to open a crafted czeeopauth:// link (e.g., from a web page or email), injecting OS commands that execute in the context of the application — the scope-changed CVSS vector (S:C with high confidentiality and integrity impact) reflects the attack crossing a trust boundary via the URL scheme. Users of eObčanka-Identifikace on macOS running any version prior to 3.6.0 are affected. There is no evidence of exploitation in the wild: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only about a 0.8% chance of exploitation within 30 days.

What to do: Upgrade eObčanka-Identifikace on macOS to version 3.6.0 or later, which sanitizes URL scheme parameters. As an interim mitigation, avoid opening czeeopauth:// links from untrusted sources and verify the installed version of the app on managed Macs.

Affected
Digitální a informační agentura (DIA) eObčanka-Identifikace (macOS)all versions prior to 3.6.0
Estimated exposure
moderateon the order of tens of thousands of macOS users (unpublished installed base; estimated as the macOS share of Czech eObčanka/eID holders) — The app is the macOS component of the Czech national eID (eObčanka) authentication tooling, so its installed base is limited to Czech eID users who authenticate from Mac desktops — plausibly a tens-of-thousands-scale subset of a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for parameterized application execution. Prior to version 3.6.0, incoming URL parameters were passed to the compiled AppleScript wrapper using concatenation without sufficient sanitization.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.