← Back to browse · API

CVE-2026-56415

Severity
CRITICAL
CVSS
10.0
EPSS
0.03148
Risk score
41.1
CISA KEV
No
PoC
No
Published
2026-06-30
Modified
2026-07-01
First seen
2026-08-07
Aliases
EUVD-2026-40844, GHSA-P9RG-4WJX-JM87
Products
StoneFly:Storage Concentrator 0 <8.0.4.22, StoneFly:Storage Concentrator Virtual Machine 0 <8.0.4.22
Sources
euvd EUVD-2026-40844

Description

Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is processed without adequate input sanitization, resulting in arbitrary command execution with root-level privileges on the underlying system.

References