rootpwn

critical · CVSS v3 9.9 · EPSS 0.00464

CVE-2026-93698

CVE-2026-93698 exposes the Multilang adminbin to arbitrary command execution due to insufficient input validation. Attackers can run any sys

Overview

CVE-2026-93698 exposes the Multilang adminbin to arbitrary command execution due to insufficient input validation. Attackers can run any system command via the admin interface, potentially compromising the entire host. This flaw is critical and can be exploited remotely by authenticated or unauthenticated users with admin access.

Description

Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.

Impact

The vulnerability allows attackers to compromise confidentiality, integrity, and availability of the affected system. Administrators and operators are directly impacted as they can be coerced into executing malicious commands. The flaw can lead to full system takeover, data exfiltration, and service disruption.

Remediation

Apply the vendor’s security patch that validates adminbin input or upgrade to the latest version. Restrict adminbin access to trusted IP ranges and enforce least privilege. Disable remote execution features if not required, and monitor logs for suspicious command activity.

Risk context

Severity is critical with a CVSS v3 score of 9.9. The EPSS score of 0.00464 indicates a low probability of exploitation, but the high impact warrants immediate attention. Defenders should prioritize patching and hardening.

Affected products

  • Multilang adminbin

Scores

Severity
critical
CVSS v2
9
CVSS v3
9.9
CVSS v4
—
EPSS
0.00464

arbitrary-command-execution adminbin critical input-validation privilege-escalation remote-execution

← All CVEs