Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

Owl opds 2.2.0.4 allows attackers to execute unauthorized commands

CVE-2026-26093
Summary

A security issue in Owl opds 2.2.0.4 allows an attacker to potentially execute unauthorized commands on your system. This means that a malicious user could potentially take control of your system or disrupt its normal functioning. To protect yourself, update to the latest version of Owl opds.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
owlcyberdefense opds-talon 2.2.0.4
owlcyberdefense opds-talon 2.2.0.4
Original title
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command Injection via a crafted network request.
Original description
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command Injection via a crafted network request.
nvd CVSS3.1 9.8
nvd CVSS4.0 8.7
Vulnerability type
CWE-77 Command Injection
Published: 20 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026