ZeroHour

CVE-2026-82766

Authenticated OS Command Injection in SGA1000

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-82766 is an OS command injection flaw (CWE-78) in the product known as SGA1000: the software fails to neutralize special elements in user-supplied input before it is used in an operating-system command. Exploitation requires a valid login — the CVSS v4.0 vector (AV:N/AC:L/PR:L, score 8.7 High) means a remote, authenticated attacker with low privileges can submit crafted input via the product's network-accessible interface and have it executed as an arbitrary OS command on the product. Successful exploitation gives the attacker full control of the affected system, with high impact on its confidentiality, integrity and availability (e.g., credential or configuration theft, tampering, or rendering the product unusable), although the impact is limited to the product itself rather than other systems on the network. Anyone running SGA1000 should be considered potentially affected; the advisory data provided does not name a vendor or specific version ranges, so scope should be confirmed with the vendor's advisory (CVE assigned by JPCERT/INCIDENT, suggesting a Japan-market vendor). No public proof-of-concept exists and the flaw is not in CISA's KEV catalog, so exploitation has not been observed in the wild, though the authentication requirement means attackers would need valid or default credentials, stolen sessions, or an insider position.

What to do: Check the vendor's or JPCERT/JVN advisory for a fixed firmware/software release and upgrade as soon as one is available. Until then, keep the SGA1000 management interface off the public internet — place it on a restricted management VLAN or behind a VPN with firewall allowlists — and rotate credentials and disable unused accounts, since exploitation requires a valid login. Review the product's logs for unexpected commands or suspicious administrative logins.

Affected
SGA1000
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.