Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-107202: h-ui admin API allows root command execution

CVE-2026-107202 · published 3 days ago
Summary

The h-ui web‑admin interface (versions up to 0.0.25) lets a logged‑in administrator enter data that is turned into a system firewall command without proper checks. This can let an attacker run any operating‑system command on the server with full administrator rights. Upgrade to a newer version or apply the vendor's patch and ensure only trusted administrators have access.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
jonssonyan h-ui 0.0.25
Original advisory text
CVE-2026-107202
A command injection vulnerability exists in the h-ui (version v0.0.25 and below) administrative API due to improper validation of the listen configuration field. When an authenticated administrator submits a value containing shell metacharacters, the application constructs nftables/iptables rule strings using fmt.Sprintf and executes them via bash -c as root. Because the listen field lacks port or format validation, arbitrary OS commands can be injected and executed with root privileges.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-78OS Command Injection
CWE-77Command Injection
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-107202 · MITRE
Track software like this
Free during beta