CVE-2026-57499
Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)
CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th
Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands on the Liman server. The `ip_address` parameter is embedded directly into a shell command without sanitization, enabling shell escape via single-quote injection. This is fixed in 2.2.2 - 1103.
| CWE | CWE-20 CWE-78 |
| Vendor | limanmys |
| Product | core |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for limanmys core
Be the first to know when new critical vulnerabilities affecting limanmys core are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
limanmys / core
< 2.2.2 - 1103