Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-34114: Guardian language-system allows arbitrary OS command execution
CVE-2026-34114
CVE-2026-34114
Summary
The Guardian language-system has a security issue that allows an attacker to execute commands on the server without needing a login. This is a serious problem because it can allow the attacker to access and modify sensitive data. To fix this, the developers should update the code to properly sanitize the input data before executing any commands.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| guardian | language-system | <= e42c395ec4b03fe62973a669c9209a673838b8a4 |
Original title
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in translate_text.php
Original description
Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) without sanitization: exec(\"php jobs/translate_text.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server.
nvd CVSS3.1
9.8
nvd CVSS4.0
9.3
Vulnerability type
CWE-78
OS Command Injection
Published: 1 Jul 2026 · Updated: 23 Jul 2026 · First seen: 1 Jul 2026