CVE-2023-50094: Yogeshojha Rengine

High severity, CVSS 8.8. EPSS: 13.5% chance of exploitation in the next 30 days.

reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.

Affected products

Published 2024-01-01. Last modified 2026-06-17.