CVE-2026-3120

7.2

Profelis Information and Consulting Trade and Industry Limited Company · SambaBox

A code injection vulnerability in SambaBox allows authenticated high-privilege attackers to achieve OS command injection.

Executive summary

An improper code generation flaw in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows high-privilege attackers to execute arbitrary OS commands, posing a critical risk to underlying system integrity.

Vulnerability

This flaw is classified as a code injection vulnerability, specifically CWE-94, which permits OS command injection. The CVSS vector indicates that the attack vector is network-based with low attack complexity, though it requires high privileges for successful exploitation without user interaction.

Business impact

A successful exploitation of this vulnerability could grant an attacker complete control over the host operating system, leading to total confidentiality, integrity, and availability loss. Given the CVSS score of 7.2, the business impact is severe, potentially resulting in unauthorized data access, system disruption, and extensive operational downtime.

Remediation

Immediate Action: Apply the vendor security updates immediately to upgrade SambaBox to version 5.3 or later.

Proactive Monitoring: Monitor system logs for anomalous process creation, unexpected command-line arguments, and unauthorized administrative activities.

Compensating Controls: Restrict administrative network access to trusted management subnets and enforce strict least-privilege principles to limit the potential fallout from compromised accounts.

Exploitation status

Public Exploit Available: false

Analyst recommendation

System administrators must treat this high-severity vulnerability with urgency. Apply the available vendor updates immediately to secure the SambaBox installation and prevent potential OS command execution.

Sources

Originally found and disclosed by Kayra BÜYÜKLÜ, per the CVE Program record.