go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

HGiga|iSherlock - OS Command Injection

TVN ID TVN-202604002
CVE ID CVE-2026-6349
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Affected Products:
Hgiga iSherlock 4.5 and 5.5(including MailSherlock、SpamSherlock、AuditSherlock)

Affected Packages:
iSherlock-base-4.5 before version 476
iSherlock-audit-4.5 before version 261
iSherlock-base-5.5 before version 476
iSherlock-audit-5.5 before version 261
Description The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
Solution Update iSherlock-base-4.5 package to version 476 or later
Update iSherlock-audit-4.5 package to version 261 or later
Update iSherlock-base-5.5 package to version 476 or later
Update iSherlock-audit-5.5 package to version 261 or later
Credit Ting-Wei Hsieh, Jun-Yi Dai (CHT Security)
Public Date 2026-04-16
Top