CVE-2026-41225
A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role
A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CRITICAL · CVSS 9.1
EPSS 0.00089
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0