CVE-2026-107202
Received Received - Intake

Command Injection in H-UI Admin API

Vulnerability report for CVE-2026-107202, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: CERT/CC

Description

A command injection vulnerability exists in the h-ui (version v0.0.25 and below) administrative API due to improper validation of the listen configuration field. When an authenticated administrator submits a value containing shell metacharacters, the application constructs nftables/iptables rule strings using fmt.Sprintf and executes them via bash -c as root. Because the listen field lacks port or format validation, arbitrary OS commands can be injected and executed with root privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jonssonyan h-ui 0.0.25

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a command injection flaw in the h-ui administrative API (version v0.0.25 and below). It occurs because the listen configuration field does not properly validate input. Attackers with admin access can inject shell metacharacters into this field, which the application then uses to construct and execute nftables/iptables rule strings via bash -c as root. This allows arbitrary OS commands to run with root privileges.

Detection Guidance

To detect this vulnerability, inspect the h-ui administrative API logs for unusual nftables/iptables rule modifications or commands executed via bash -c. Check for shell metacharacters in the listen configuration field. Review system logs for unexpected root-level command executions.

Impact Analysis

If you use h-ui v0.0.25 or below, an authenticated attacker could exploit this to execute arbitrary commands on your system with root privileges. This could lead to full system compromise, data theft, or unauthorized modifications. Unpatched systems are at high risk if exposed to trusted administrators or if credentials are compromised.

Compliance Impact

This vulnerability could violate compliance requirements under GDPR (data protection) and HIPAA (health data security) by enabling unauthorized access to sensitive systems. Exploitation may lead to data breaches, unauthorized modifications, or loss of audit trails, all of which are critical violations for these regulations.

Mitigation Strategies

Immediately update h-ui to a version above v0.0.25. Disable or restrict access to the administrative API until patched. Monitor network traffic for unauthorized command executions. Implement input validation for the listen field to block shell metacharacters.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107202. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart