---
id: CVE-2026-78797
title: >-
  An issue in iStoreOS istoreos-24.10.7 and before allows a remote attacker to
  execute arbitrary code via the task_id in tasks-lib.lua.
summary: >-
  An issue in iStoreOS istoreos-24.10.7 and before allows a remote attacker to
  execute arbitrary code via the task_id in tasks-lib.lua.
severity: none
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T20:17:11.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78797'
references:
  - url: 'https://doc.linkease.com/zh/guide/istoreos/install_vmware.html'
    label: cve@mitre.org
  - url: 'https://fw.koolcenter.com/iStoreOS/x86_64_efi/'
    label: cve@mitre.org
  - url: >-
      https://github.com/PRISMI-Team/VulnDisclos/blob/main/Routers/iStoreOS/authorized-rce.md
    label: cve@mitre.org
  - url: 'https://github.com/istoreos/istoreos'
    label: cve@mitre.org
  - url: 'https://pastebin.com/zFVpUjxW'
    label: cve@mitre.org
tags:
  - nvd
ingestedAt: '2026-10-09T21:12:42.319Z'
---

## Overview

An issue in iStoreOS istoreos-24.10.7 and before allows a remote attacker to execute arbitrary code via the task_id in tasks-lib.lua.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
