Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35581

25
FAUCET Score

Emissary versions prior to 8.39.0 contain a command injection vulnerability in the Executrix utility class, which constructs shell commands by concatenating configuration-derived values with insufficient input sanitization. The flaw allows shell metacharacters to bypass filters that only replace spaces with underscores, enabling arbitrary command execution through the PLACE_NAME parameter. This vulnerability affects Emissary's P2P-based workflow engine across all affected versions until the 8.39.0 patch. The vulnerability carries a CVSS score of 7.2 (HIGH) with a network-based attack vector requiring high-level privileges and no user interaction. Exploitation results in complete system compromise, including high-impact confidentiality, integrity, and availability breaches through direct shell command execution. The attack has low complexity, making it straightforward to exploit once an attacker gains privileged access to configure the affected parameter. There is no evidence of active exploitation in the wild, as indicated by the absence of KEV designation and inactive status on security hotlists. The EPSS score of 0.00087 suggests minimal real-world exploitation probability. However, organizations running Emissary versions before 8.39.0 should prioritize patching immediately, as the vulnerability is trivial to exploit for any authenticated administrator with configuration access.

Impacted Technologies

VendorProductVersion(s)CPE
<= 8.38.0CPE matchmatch criteria
cpe:2.3:a:nsa:emissary:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.56%
Probability of exploitation in next 30 days
EPSS Percentile
43.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0056 is in the 21st percentile among its peer group of 5,537 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

mavenpatch availablevia ghsa
Product: gov.nsa.emissary:emissaryFixed in: 8.39.0

Vendor Advisories (1)

mavenGHSA-6c37-7w4p-jg9vhigh

Emissary has a Command Injection via PLACE_NAME Configuration in Executrix

Apr 8, 2026

References

github.com / NationalSecurityAgency/emissary/security/advisories/GHSA-6c37-7w4p-jg9v
ExploitVendor Advisory