CVE-2026-59111
Received Received - Intake

OS Command Injection in DIA eObčanka-Identifikace on macOS

Vulnerability report for CVE-2026-59111, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: ENISA

Description

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for parameterized application execution. Prior to version 3.6.0, incoming URL parameters were passed to the compiled AppleScript wrapper using concatenation without sufficient sanitization.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
digitální_a_informační_agentura eobčanka_identifikace to 3.6.0 (exc)
digitální_a_informační_agentura eobčanka_identifikace 3.6.0
digitální_a_informační_agentura eobčanka_identifikace 3.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an OS command injection vulnerability in the DIA eObčanka-Identifikace macOS application. It allows an attacker to execute arbitrary OS commands with the privileges of the logged-in user by tricking them into clicking a specially crafted link using the czeeopauth:// URL scheme. The issue occurs because user-supplied parameters are passed to an AppleScript wrapper without proper sanitization, enabling command termination and injection of malicious shell commands.

Detection Guidance

Check the installed version of DIA eObčanka-Identifikace on macOS using 'system_profiler SPApplicationsDataType | grep -i eObčanka'. If the version is below 3.7.0, the system is vulnerable. Monitor network traffic for unusual czeeopauth:// URL scheme requests.

Impact Analysis

An attacker could gain control over your macOS system by exploiting this flaw. They might steal sensitive data, install malware, modify system files, or perform actions on your behalf. The attack requires user interaction, such as clicking a malicious link, but could lead to full system compromise if successful.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access control. Organizations using affected versions may face compliance breaches, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Immediately update DIA eObčanka-Identifikace to version 3.7.0 or later via the official website. Avoid clicking on any czeeopauth:// links from untrusted sources. Disable or restrict custom URL scheme handling if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59111. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart