Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-34108: Guardian: Unauthenticated Remote Command Execution via GET Parameter
CVE-2026-34108
CVE-2026-34108
Summary
An unauthenticated attacker can execute arbitrary system commands on the Guardian server by appending malicious characters to the GET 'id' parameter. This can lead to unauthorized access and data manipulation. Update Guardian to sanitize the 'id' parameter before passing it to the exec() function.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| guardian | language-system | <= e42c395ec4b03fe62973a669c9209a673838b8a4 |
Original title
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in text.php
Original description
Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/text.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server.
nvd CVSS3.1
9.8
nvd CVSS4.0
9.3
Vulnerability type
CWE-78
OS Command Injection
Published: 1 Jul 2026 · Updated: 23 Jul 2026 · First seen: 1 Jul 2026