Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-56415: Storage Concentrator (SC & SCVM) command injection risk via debug.pl script

CVE-2026-56415
Summary

An attacker can submit a malicious HTTP request to the Storage Concentrator's debug.pl script without a password, potentially allowing them to execute any system command with full access. This is a serious security risk because it could allow unauthorized access to the system. To protect your system, update the Storage Concentrator software as soon as possible and ensure that the debug.pl script is not exposed to the internet.

Original title
Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTT...
Original description
Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is processed without adequate input sanitization, resulting in arbitrary command execution with root-level privileges on the underlying system.
nvd CVSS3.1 10.0
nvd CVSS4.0 10.0
Vulnerability type
CWE-78 OS Command Injection
Published: 30 Jun 2026 · Updated: 23 Jul 2026 · First seen: 1 Jul 2026