CVE-2026-71377
largeCommand Argument Injection in Hitachi Cosminexus Component Container
Hitachi's Cosminexus Component Container is affected by a command argument injection flaw (CWE-88), in which arguments passed to a spawned command are not properly delimited, allowing an attacker to inject or alter command arguments. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) indicates the issue is exploitable over the network without authentication or user interaction, and the 9.8 critical score with high confidentiality, integrity, and availability impacts implies attacker-controlled arguments could escalate to arbitrary command execution in the context of the container. Thirteen version ranges across all supported release series (09-00 through 11-70) are affected, so essentially every supported deployment of the Component Container should be treated as vulnerable pending remediation. There is no public proof of concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days, so no in-the-wild exploitation is currently known.
What to do: Upgrade each affected series to the fixed maintenance revision cited in Hitachi's advisory (11-70-03, 11-60-03, 11-20-10, 09-87-10, or 09-70-28 for the 'before'-style ranges, and the maintenance revision published after 11-50-03, 11-40-03, 11-30-08, 11-10-11, 11-00-12, 09-80-04, 09-50-22, or 09-00-18 for the remaining ranges). Because the CVSS vector indicates network exploitation without authentication, inventory where the Component Container runs, restrict network access to its service and management listeners, and prioritize any instances reachable from untrusted networks. Monitor Hitachi's advisory and the KEV feed, since no public PoC or in-the-wild exploitation is known yet.
| Hitachi Cosminexus Component Container | from 11-70-01 before 11-70-03; from 11-60 before 11-60-03; from 11-50 through 11-50-03; from 11-40 through 11-40-03; from 11-30 through 11-30-08; from 11-20 bef |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 through 11-00-12, from 09-87 before 09-87-10, from 09-80 through 09-80-04, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
- Weakness
- CWE-88
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.