Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-107202: h-ui admin API allows root command execution
CVE-2026-107202 · published 3 days ago
Summary
The h-ui web‑admin interface (versions up to 0.0.25) lets a logged‑in administrator enter data that is turned into a system firewall command without proper checks. This can let an attacker run any operating‑system command on the server with full administrator rights. Upgrade to a newer version or apply the vendor's patch and ensure only trusted administrators have access.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jonssonyan | h-ui | 0.0.25 |
Original advisory text
CVE-2026-107202
A command injection vulnerability exists in the h-ui (version v0.0.25 and below) administrative API due to improper validation of the listen configuration field. When an authenticated administrator submits a value containing shell metacharacters, the application constructs nftables/iptables rule strings using fmt.Sprintf and executes them via bash -c as root. Because the listen field lacks port or format validation, arbitrary OS commands can be injected and executed with root privileges.
References
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.1
Critical
Type
CWE-78OS Command Injection
CWE-77Command Injection
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta