NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update to version 10.1.8.3 or later.
Workaround
No workaround given by the vendor.
References
History
Tue, 21 Apr 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server. | |
| Title | NewSoft|NewSoftOA - OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-04-21T03:32:55.138Z
Reserved: 2026-04-09T10:34:42.896Z
Link: CVE-2026-5965
No data.
Status : Received
Published: 2026-04-21T04:16:13.443
Modified: 2026-04-21T04:16:13.443
Link: CVE-2026-5965
No data.
OpenCVE Enrichment
No data.
Weaknesses