CVE-2026-56415 Details
Description
Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is processed without adequate input sanitization, resulting in arbitrary command execution with root-level privileges on the underlying system.
A command injection vulnerability has been identified in the StoneFly Storage Concentrator (both SC and SCVM) within the debug.pl script. This vulnerability is accessible without authentication, allowing remote attackers to send specially crafted HTTP requests with malicious payloads. The lack of proper input sanitization enables arbitrary command execution with root privileges on the underlying system. Affected versions include Storage Concentrator and Storage Concentrator Virtual Machine versions prior to 8.0.4.22.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| StoneFly Storage Concentrator | < 8.0.4.22 < 8.0.4.26 < 8.0.4.29 |
CPE
Remediation
| |
| StoneFly Storage Concentrator Virtual Machine | < 8.0.4.22 < 8.0.4.26 < 8.0.4.29 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion