CVE-2016-15057 Details
Description
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum. This issue affects Apache Continuum: all versions. Attackers with access to the installations REST API can use this to invoke arbitrary commands on the server. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
A command injection vulnerability allowing remote code execution has been identified in Apache Continuum. This issue affects all versions of the software. The vulnerability arises from improper neutralization of special elements used in commands, which can be exploited by attackers with access to the installation's REST API to invoke arbitrary commands on the server. As Apache Continuum is a retired project, no official fix will be released. Users are advised to seek alternatives or restrict access to trusted users.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/01/26/1 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/hbvf1ztqw2kv51khvzm5nk3mml3nm4z1 | [email protected] | Mailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache continuum | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 27, 2026 | Initial Analysis | [email protected] |
| Jan 26, 2026 | CVE Modified | CVE |
| Jan 26, 2026 | CVE Modified | CISA-ADP |
| Jan 26, 2026 | New CVE Received | [email protected] |