CVE-2026-40456 Details
Description
An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address parameter being passed to the "exec()" function without proper validation, allowing attackers to execute arbitrary operating system commands.
A vulnerability allowing OS command injection exists in LMS (LAN Management System) versions prior to the commit 9fcb4de. This vulnerability arises because an IP address parameter is passed to the 'exec()' function without adequate validation, enabling attackers to execute arbitrary operating system commands.
Users can update to the latest version of LMS, which includes the necessary validation for IP address parameters. The latest version can be downloaded from the LMS GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 18, 2026CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/06/CVE-2026-40455 | [email protected] | AdvisoryBundleRemedy |
| https://github.com/chilek/lms/commit/9fcb4de19b7d76394898dbc124252b86b07ac0ed | [email protected] | Source CodeVendor |
| https://lms.org.pl/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| LMS | < 9fcb4de |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | New CVE Received | [email protected] |
| Jun 18, 2026 | CVE Modified | CISA-ADP |
Volerion