← Back to CVE List
Vulnerability Intelligence Report
OS Command Injection in Felisify Informatics' SambaBox

CVE-2026-85523

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Felisify Information Technologies Industry and Trade Inc. SambaBox allows OS Command Injection. This issue affects SambaBox: before 5.4.1.

Injection No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-78 ↗CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')

Affected Products & Versions

Vendor Product Affected Versions
Felisify Information Technologies Industry and Trade Inc. SambaBox 0 < 5.4.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Vulnerability Class
Injection

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityTR-CERT (Computer Emergency Response Team of the Republic of Türkiye) · CERT · Türkiye
Reserved2026-09-04T08:00:07
Published2026-10-06T13:55:32
Patch Date2026-10-06
Last Updated2026-10-06T19:30:35

LINK COPIED TO CLIPBOARD