Skip to main content

CVE-2026-1324

8.8
HIGHCVSS v3.1 Base Score
0.28%
LOW RiskEPSS (52nd percentile)

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionController of the file /isomp-protocol/protocol/session of the component SSH Protocol Handler. The manipulation of the argument keypassword leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Published: 1/22/2026
Modified: 1/30/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

0.28%LOW Exploitation Risk
52nd percentile

This vulnerability has a 0.28% probability of being exploited in the next 30 days, ranking higher than 52% of all scored CVEs.

Related Vulnerabilities