{"id":"CVE-2026-60121","title":"Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument …","summary":"Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument …","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"vitec","product":"flamingo","affected":["flamingo <= 4.12.2"],"published":"2026-07-13","updated":"2026-08-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-60121","references":[{"url":"https://damiri.fr/en/cve/CVE-2026-60121","label":"disclosure@vulncheck.com"},{"url":"https://www.vitec.com/solutions/iptv-distribution","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/vitec-flamingo-unauthenticated-os-command-injection-via-ping-php","label":"disclosure@vulncheck.com"}],"tags":["nvd","exploit-available"],"epss":0.02336,"epssPercentile":0.82837,"ingestedAt":"2026-08-15T13:26:46.544Z","exploits":{"github":1,"githubRepos":["https://github.com/HORKimhab/CVE-2026-60121-CVE-2026-61498"],"checkedAt":"2026-09-23T07:14:28.393Z"},"exploitAvailable":true,"slug":"CVE-2026-60121","body":"## Overview\n\nVitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling. The endpoint applies escapeshellarg() to the user-supplied host POST parameter before passing it to a system wrapper, but the wrapper retrieves the decoded value from argv and incorporates it into a second shell_exec() call without escaping, allowing injected commands to execute with root privileges via passwordless sudo.\n\n## Affected\n\n- `flamingo <= 4.12.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.5,"exploitation":12,"ransomware":0},"changes":[{"seq":5388,"id":"CVE-2026-60121","ts":1788887275754,"field":"exploit_available","old":"false","new":"true"},{"seq":4271,"id":"CVE-2026-60121","ts":1788886390410,"field":"exploit_available","old":"true","new":"false"},{"seq":3020,"id":"CVE-2026-60121","ts":1788883054015,"field":"exploit_available","old":"false","new":"true"},{"seq":2049,"id":"CVE-2026-60121","ts":1788882458227,"field":"exploit_available","old":"true","new":"false"},{"seq":1123,"id":"CVE-2026-60121","ts":1788881895265,"field":"exploit_available","old":"false","new":"true"}]}