Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-61498: Vitec Flamingo 4.12.2 Allows Unauthenticated Command Execution
CVE-2026-61498
CVE-2026-61498
Summary
The Vitec Flamingo 4.12.2 software has a security issue that lets hackers execute system commands without needing a password. This is a serious risk because hackers can access sensitive system settings. Update the software to a patched version to prevent unauthorized command execution.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| vitec | flamingo | 4.12.2 |
Original title
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary comm...
Original description
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters. Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-supplied values directly to shell commands via passthru(), to execute arbitrary OS commands with root privileges due to the web server context having passwordless sudo access.
mitre CVSS3.1
9.8
Vulnerability type
CWE-78
OS Command Injection
- https://damiri.fr/en/cve/CVE-2026-61498 technical-description exploit
- https://www.vitec.com/solutions/iptv-distribution product
- https://www.vulncheck.com/advisories/vitec-flamingo-unauthenticated-os-command-i... third-party-advisory
Published: 13 Jul 2026 · Updated: 20 Jul 2026 · First seen: 13 Jul 2026