{"id":"CVE-2026-15027","title":"CGServiSign developed by Changing has a OS Command Injection vulnerability","summary":"CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"Changing","product":"CGServiSign","affected":["CGServiSign 1.0.23.1227"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T15:17:11.253","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-15027","references":[{"url":"https://www.twcert.org.tw/en/cp-139-11214-89281-2.html","label":"twcert@cert.org.tw"},{"url":"https://www.twcert.org.tw/tw/cp-132-11213-28a81-1.html","label":"twcert@cert.org.tw"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-23T14:10:48.482227Z"},"epss":0.02173,"epssPercentile":0.81535,"ingestedAt":"2026-09-23T09:21:16.965Z","slug":"CVE-2026-15027","body":"## Overview\n\nCGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}