LIVE · cybersecurity feed
Live wire
cve record

CVE-2026-23920

Published
CVSS—
Severitynone
WeaknessCWE-78
ExploitedNot in CISA KEV

Description

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-23920

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-23920.