CVE-2026-6349: Hgiga Isherlock-Audit-4.5
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
Affected products
- Hgiga Isherlock-Audit-4.5: before 261 (fixed in 261)
- Hgiga Isherlock-Audit-5.5: before 261 (fixed in 261)
- Hgiga Isherlock-Base-4.5: before 476 (fixed in 476)
- Hgiga Isherlock-Base-5.5: before 476 (fixed in 476)
Published 2026-04-16. Last modified 2026-06-17.