CVE-2026-71377
Received
Received - Intake
Command Argument Injection in Cosminexus Component Container
Vulnerability report for CVE-2026-71377, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-08
Last updated on: 2026-09-08
Assigner: Hitachi, Ltd.
Description
Description
Command Argument Injection Vulnerability in Cosminexus Component Container.
This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 through 11-00-12, from 09-87 before 09-87-10, from 09-80 through 09-80-04, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hitachi | cosminexus_component_container | From 11-70-01 (inc) to 11-70-03 (exc) |
| hitachi | cosminexus_component_container | From 11-60 (inc) to 11-60-03 (exc) |
| hitachi | cosminexus_component_container | From 11-50 (inc) to 11-50-03 (inc) |
| hitachi | cosminexus_component_container | From 11-40 (inc) to 11-40-03 (inc) |
| hitachi | cosminexus_component_container | From 11-30 (inc) to 11-30-08 (inc) |
| hitachi | cosminexus_component_container | From 11-20 (inc) to 11-20-10 (exc) |
| hitachi | cosminexus_component_container | From 11-10 (inc) to 11-10-11 (inc) |
| hitachi | cosminexus_component_container | From 11-00 (inc) to 11-00-12 (inc) |
| hitachi | cosminexus_component_container | From 09-87 (inc) to 09-87-10 (exc) |
| hitachi | cosminexus_component_container | From 09-80 (inc) to 09-80-04 (inc) |
| hitachi | cosminexus_component_container | From 09-70 (inc) to 09-70-28 (exc) |
| hitachi | cosminexus_component_container | From 09-50 (inc) to 09-50-22 (inc) |
| hitachi | cosminexus_component_container | From 09-00 (inc) to 09-00-18 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-88 | The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string. |