Ghostwire

CVE-2026-9645: Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts...

CRITICAL CVSS 9.9

Published: May 28, 2026 | Last Modified: May 28, 2026

Description

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References