216.73.216.233

CVE-2026-22781

· Published 12/01/2026 19:16 · Modified 13/01/2026 14:03

Labels: CVE-2026-22781 2026-01-12CVE-2026-22781CWE-78[email protected]

Essential information

Published
12/01/2026 19:16
Modified
13/01/2026 14:03
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via CGI ISINDEX-style query parameters. The query parameters are passed as command-line arguments to the CGI executable via Windows CreateProcess(). An unauthenticated remote attacker can execute arbitrary commands on the server by injecting Windows shell metacharacters into HTTP requests. This vulnerability is fixed in 1.98.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tinyweb / tinyweb cpe:2.3:a:tinyweb:tinyweb:*:<1.98:*:*:*:*:*:*

References