critical · CVSS v3 9.9 · EPSS 0.00464
CVE-2026-93698
CVE-2026-93698 exposes the Multilang adminbin to arbitrary command execution due to insufficient input validation. Attackers can run any sys
Overview
CVE-2026-93698 exposes the Multilang adminbin to arbitrary command execution due to insufficient input validation. Attackers can run any system command via the admin interface, potentially compromising the entire host. This flaw is critical and can be exploited remotely by authenticated or unauthenticated users with admin access.
Description
Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
Impact
The vulnerability allows attackers to compromise confidentiality, integrity, and availability of the affected system. Administrators and operators are directly impacted as they can be coerced into executing malicious commands. The flaw can lead to full system takeover, data exfiltration, and service disruption.
Remediation
Apply the vendor’s security patch that validates adminbin input or upgrade to the latest version. Restrict adminbin access to trusted IP ranges and enforce least privilege. Disable remote execution features if not required, and monitor logs for suspicious command activity.
Risk context
Severity is critical with a CVSS v3 score of 9.9. The EPSS score of 0.00464 indicates a low probability of exploitation, but the high impact warrants immediate attention. Defenders should prioritize patching and hardening.
Affected products
- Multilang adminbin
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 9.9
- CVSS v4
- —
- EPSS
- 0.00464