Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-34116: Guardian Language System Unauthenticated Command Execution

CVE-2026-34116 CVE-2026-34116
Summary

The Guardian language system has a security flaw that allows an attacker to execute arbitrary commands on the server without needing a password. This can happen if an attacker sends a specially crafted request to the system. To fix this, update the Guardian language system to properly sanitize user input and restrict access to authorized users only.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
guardian language-system <= e42c395ec4b03fe62973a669c9209a673838b8a4
Original title
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe.php
Original description
Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without sanitization: exec(\"php jobs/transcribe.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server.
nvd CVSS3.1 9.8
nvd CVSS4.0 9.3
Vulnerability type
CWE-78 OS Command Injection
Published: 1 Jul 2026 · Updated: 23 Jul 2026 · First seen: 1 Jul 2026