CVE-2026-8431High· 7.2▾ TwilightAn administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax. This issue affects all MongoDB Ops Manager 7.0 versio…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
0.4% → 0.7%
An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax.
This issue affects all MongoDB Ops Manager 7.0 versions and MongoDB Ops Manager versions 8.0.22 and prior.
ops_manager >= 7.0.0, < 8.0.23Upgrade past the affected range:
ops_manager 8.0.23Connected by shared product, vendor, weakness, or advisory.
CVE-2025-15391Medium· 6.3A weakness has been identified in D-Link DIR-806A 100CNb11
CVE-2025-13799Medium· 6.3A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c
CVE-2025-13797Medium· 6.3A vulnerability was detected in ADSLR B-QE2W401 250814-r037c
CVE-2019-25029Critical· 9.8In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application
CVE-2018-19949Critical· 9.8If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands
CVE-2024-55956Critical· 9.8In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…