CVE-2024-26260: Hgiga Oaklouds-Organization-2.0

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without permission.

Affected products

  • Hgiga Oaklouds-Organization-2.0: before 188 (fixed in 188)
  • Hgiga Oaklouds-Organization-3.0: before 188 (fixed in 188)
  • Hgiga Oaklouds-Webbase-2.0: before 1051 (fixed in 1051)
  • Hgiga Oaklouds-Webbase-3.0: before 1051 (fixed in 1051)

Published 2024-02-15. Last modified 2026-06-17.