CVE-2026-3066 is a critical command injection vulnerability affecting HummerRisk up to version 1.5.0, specifically within the fixedCommand function of the PlatformUtils.java file in the Cloud Compliance Scanning component. This flaw carries a high CVSS score of 8.8, indicating that an unauthenticated attacker can remotely execute arbitrary commands with high impact on confidentiality, integrity, and availability. While the vendor has not responded to disclosure, a public exploit exists, increasing the immediate risk of exploitation. Despite the availability of an exploit, there is currently no evidence of active exploitation in the wild, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.5.0CPE matchmatch criteria | cpe:2.3:a:hummerrisk:hummerrisk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.