CVE-2026-5967 is a privilege escalation vulnerability in TeamT5's ThreatSonar Anti-Ransomware product that allows authenticated remote attackers with shell access to inject arbitrary operating system commands and execute them with root-level privileges. This vulnerability affects the core functionality of a security tool designed to protect against ransomware threats. The attack requires network access and valid authentication credentials but no user interaction, resulting in a CVSS 3.1 score of 8.8 (HIGH) with complete compromise of confidentiality, integrity, and availability. Exploitation status indicates this vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hot lists, suggesting limited active exploitation in the wild. However, the FAUCET Risk Score of 52.0/100 indicates moderate concern, and organizations running ThreatSonar should prioritize patching given the severe impact potential if an authenticated attacker gains system access.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 4.0.0CPE match | cpe:2.3:a:teamt5:threatsonar_anti-ransomware:*:*:*:*:*:*:*:* | ||
< 4.0.0CPE matchmatch criteria | cpe:2.3:a:teamt5:threatsonar_anti-ransomware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.