← Back to browse · API

CVE-2026-22781

Severity
CRITICAL
CVSS
10.0
EPSS
0.02212
Risk score
40.77
CISA KEV
No
PoC
No
Published
2026-01-12
Modified
2026-01-12
First seen
2026-08-07
Aliases
EUVD-2026-2005
Products
maximmasiutin:TinyWeb < 1.98
Sources
euvd EUVD-2026-2005

Description

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via CGI ISINDEX-style query parameters. The query parameters are passed as command-line arguments to the CGI executable via Windows CreateProcess(). An unauthenticated remote attacker can execute arbitrary commands on the server by injecting Windows shell metacharacters into HTTP requests. This vulnerability is fixed in 1.98.

References