CVE-2022-26151 is a command injection vulnerability affecting Citrix XenMobile Server versions 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4. This high-severity vulnerability (CVSS 7.2) allows an attacker to execute arbitrary commands, leading to complete compromise of confidentiality, integrity, and availability, though it requires high privileges to exploit. There is no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable. Community discussion and media coverage are minimal, with only one mention and one article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.13.0CPE matchmatch criteria | cpe:2.3:a:citrix:xenmobile_server:10.13.0:-:*:*:*:*:*:* | ||
10.13.0CPE matchmatch criteria | cpe:2.3:a:citrix:xenmobile_server:10.13.0:rolling_patch_3:*:*:*:*:*:* | ||
10.13.0CPE matchmatch criteria | cpe:2.3:a:citrix:xenmobile_server:10.13.0:rolling_patch_4:*:*:*:*:*:* | ||
10.13.0CPE matchmatch criteria | cpe:2.3:a:citrix:xenmobile_server:10.13.0:rolling_patch_5:*:*:*:*:*:* | ||
10.13.0CPE matchmatch criteria | cpe:2.3:a:citrix:xenmobile_server:10.13.0:rolling_patch_6:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.