ZeroHour

CVE-2026-71376

large

Unauthenticated OS Command Injection in Hitachi Cosminexus Component Container

CVSS 3.1
9.8 critical
EPSS
<1%p60
Published
()
Modified
AI analysis

Cosminexus Component Container, the application server runtime in Hitachi's Cosminexus/uCosminexus platform, contains an OS command injection flaw (CWE-78). Per the CVSS vector, it is exploitable over the network with no authentication and no user interaction, meaning a remote attacker can trigger it by sending crafted input to a network-reachable Component Container service. Successful exploitation yields unauthenticated remote command execution on the host, with high impact to confidentiality, integrity, and availability. Any installation running an affected maintenance version in the 09-00 through 11-70 release lines is exposed, spanning both legacy and current product lines. Exploitation has not been confirmed: there is no known in-the-wild activity, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns roughly a 1% chance of exploitation within 30 days.

What to do: Inventory all servers running Cosminexus Component Container and upgrade each affected maintenance line to the fixed update named in Hitachi's advisory — at minimum 11-70-03, 11-60-03, 11-20-10, 11-00-13, 09-87-10, 09-80-05, and 09-70-28, and for lines where the advisory's range has no stated fix boundary (11-50, 11-40, 11-30, 11-10, 09-50, 09-00) apply the fixed maintenance update Hitachi specifies for that line. Until patching is complete, restrict network access to hosts running Component Container and prioritize auditing any instances reachable from untrusted networks or the internet, given the unauthenticated network-exploitable CVSS vector.

Affected
Hitachi Cosminexus Component Containerfrom 11-70-01 before 11-70-03
Hitachi Cosminexus Component Containerfrom 11-60 before 11-60-03
Hitachi Cosminexus Component Containerfrom 11-50 through 11-50-03
Hitachi Cosminexus Component Containerfrom 11-40 through 11-40-03
Hitachi Cosminexus Component Containerfrom 11-30 through 11-30-08
Hitachi Cosminexus Component Containerfrom 11-20 before 11-20-10
Hitachi Cosminexus Component Containerfrom 11-10 through 11-10-11
Hitachi Cosminexus Component Containerfrom 11-00 before 11-00-13
Hitachi Cosminexus Component Containerfrom 09-87 before 09-87-10
Hitachi Cosminexus Component Containerfrom 09-80 before 09-80-05
Hitachi Cosminexus Component Containerfrom 09-70 before 09-70-28
Hitachi Cosminexus Component Containerfrom 09-50 through 09-50-22
Estimated exposure
large≈10,000–100,000 enterprise deployments (order-of-magnitude estimate), concentrated in Japan; the directly internet-exposed subset is likely far smaller — No public install-base or internet-scan counts are available, so this estimate is based on Component Container's role as the runtime of Hitachi's long-running enterprise application server, typically deployed per-server inside Japanese…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.