8.2
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Description
Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash commands in alert names
Basic Information
ID
CVE-2026-5208
Source
GitLab
Published
Apr 8, 2026 at 11:36
Modified
Apr 8, 2026 at 12:55
Affected Product
Vendor
CoolerControl
Product
coolercontrold
Version
3.1.0
Affected Versions
CoolerControl coolercontrold 3.1.0