CVE-2026-105487
Deferred Deferred - Pending Action

OS Command Injection in reNgine listTargets Endpoint

Vulnerability report for CVE-2026-105487, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulDB

Description

A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the function subdomain_discovery of the file web/reNgine/tasks.py of the component listTargets Endpoint. The manipulation of the argument Name results in os command injection. The attack can be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
yogeshojha reNgine 2.0
yogeshojha reNgine 2.1
yogeshojha reNgine 2.2.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authenticated command injection flaw in the reNgine reconnaissance framework up to version 2.2.0. It exists in the listTargets endpoint where the Name argument can be manipulated to inject malicious shell commands. The attack is possible because the endpoint allowed POST, PUT, and DELETE requests without proper validation, enabling users to execute arbitrary commands on the server with the privileges of the reNgine process, typically root.

Detection Guidance

To detect this vulnerability, check if your reNgine instance is running version 2.2.0 or earlier. Inspect the /api/listTargets/ endpoint for unauthorized POST, PUT, PATCH, or DELETE requests. Monitor logs for unexpected command execution patterns or shell metacharacters in target names.

Impact Analysis

An attacker with authenticated access could exploit this to execute arbitrary commands on the reNgine server. This could lead to complete system compromise, allowing theft of sensitive data, API keys, project information, or enabling pivoting into internal networks. The impact includes full remote code execution with root privileges on the server hosting reNgine.

Compliance Impact

This vulnerability could lead to unauthorized remote code execution on the ReNgine server, potentially exposing sensitive data such as API keys, project information, or reconnaissance results. For organizations handling personal data under GDPR, this could result in data breaches, unauthorized access, or data exfiltration, violating principles of data protection and security. Under HIPAA, if the system processes protected health information, the breach could lead to unauthorized disclosure, compromising patient confidentiality and compliance with security rules.

Mitigation Strategies

Upgrade reNgine to the latest version where the fix is applied. Restrict the /api/listTargets/ endpoint to GET requests only. Ensure proper role-based access control is enforced. Review and validate all target names to prevent command injection. Avoid using shell=True in command execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105487. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart