---
id: CVE-2026-85523
title: >-
  Improper neutralization of special elements used in an OS command ('OS command
  injection') vulnerability in Felisify Information Technologies Industry and
  Trade Inc
summary: >-
  Improper neutralization of special elements used in an OS command ('OS command
  injection') vulnerability in Felisify Information Technologies Industry and
  Trade Inc. SambaBox allows OS Command Injection.


  This issue affects SambaBox: bef…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: Felisify Information Technologies Industry and Trade Inc.
product: SambaBox
affected:
  - SambaBox < 5.4.1
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T15:03:59.427'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85523'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1258'
    label: iletisim@usom.gov.tr
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T14:00:19.136Z'
---

## Overview

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Felisify Information Technologies Industry and Trade Inc. SambaBox allows OS Command Injection.

This issue affects SambaBox: before 5.4.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
