Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-61498: Vitec Flamingo 4.12.2 Allows Unauthenticated Command Execution

CVE-2026-61498 CVE-2026-61498
Summary

The Vitec Flamingo 4.12.2 software has a security issue that lets hackers execute system commands without needing a password. This is a serious risk because hackers can access sensitive system settings. Update the software to a patched version to prevent unauthorized command execution.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
vitec flamingo 4.12.2
Original title
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary comm...
Original description
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters. Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-supplied values directly to shell commands via passthru(), to execute arbitrary OS commands with root privileges due to the web server context having passwordless sudo access.
mitre CVSS3.1 9.8
Vulnerability type
CWE-78 OS Command Injection
Published: 13 Jul 2026 · Updated: 20 Jul 2026 · First seen: 13 Jul 2026