CVE-2026-3120: Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and...
HIGH
CVSS 7.5
Published: May 4, 2026 | Last Modified: May 4, 2026
Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection. This issue affects SambaBox: from 5.1 before 5.3.
Ghostwire Analysis — What This Means Practically
- High CVSS score indicates significant risk — exploitation could lead to substantial data exposure or system compromise.
- 4 articles from independent security sources have covered this vulnerability, indicating significant industry attention.
This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.
Security Coverage (4 articles)
References