THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-90770 (HIGH 8.8) — Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /mo

[NVD] CVE-2026-90770 (HIGH 8.8) — Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /mo

mednvdPublished 2026-09-13

CVE-2026-90770 CVSS: 8.8 HIGH Published: 2026-09-13T11:17:01.453

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/run_test/ endpoint to execute arbitrary commands

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90770