{"id":"CVE-2026-71235","title":"Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive","summary":"Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Lua script engine (re/lua.go) performs no input validation at all and preloads danger…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-94"],"published":"2026-08-05","updated":"2026-08-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71235","references":[{"url":"https://github.com/absmach/magistrala","label":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-71235.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-71235"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2511475"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-71235"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71235"},{"url":"https://access.redhat.com/errata/RHSA-2026:59467"},{"url":"https://access.redhat.com/errata/RHSA-2026:66022"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00288,"epssPercentile":0.21613,"ingestedAt":"2026-08-10T12:39:48.807Z","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","cert_manager_operator_for_red_hat_openshift","confidential_compute_attestation","deployment_validation_operator","fence_agents_remediation_operator","machine_deletion_remediation_operator","migration_toolkit_for_applications 8","migration_toolkit_for_containers","multicluster_engine_for_kubernetes","node_healthcheck_operator","openshift_lightspeed","openshift_serverless","power_monitoring_for_red_hat_openshift","advanced_cluster_management_for_kubernetes 2","ansible_automation_platform 2","certification_program_for_red_hat_enterprise_linux 9","enterprise_linux 10","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","enterprise_linux_ai_rhel_ai 3","lightspeed_for_runtimes_operator","openshift_cluster_manager_cli","openshift_container_platform 4","openshift_dev_spaces","openshift_dev_workspaces_operator","openshift_for_windows_containers","openshift_on_aws","openstack_platform 16.2","openstack_platform 17.1","openstack_platform 18.0","service_interconnect 2","web_terminal","zero_trust_workload_identity_manager_tech_preview","openshift_api_for_data_protection 1.4"],"patched":["openshift_api_for_data_protection 1.4"],"slug":"CVE-2026-71235","body":"## Overview\n\nMagistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:59467** · Red Hat · fixed in: OpenShift API for Data Protection 1.4 · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:59467)\n- **Red Hat VEX** · Important · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, cert-manager Operator for Red Hat OpenShift, Confidential Compute Attestation, Deployment Validation Operator, Fence Agents Remediation Operator, Machine Deletion Remediation Operator, … · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Zero Trust Workload Identity Manager - Tech Preview, … · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-71235.json)\n- **RHSA-2026:66022** · Red Hat · fixed in: OpenShift API for Data Protection 1.5 · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:66022)","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}