Security Advisory

CVE-2026-32968

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-03-23 11:16:01
Last updated 2026-03-23 13:51:18
Assigner CERTVDE
CVSS score 9.8
State PUBLISHED

Description

Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383.