CVE-2026-22208Disclosure

LOWCVSS 9.4 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerability via an unrestricted Lua interpreter. The Portrayal Engine initializes Lua using luaL_openlibs() without sandboxing or capability restrictions, exposing standard libraries such as 'os' and 'io' to untrusted portrayal catalogues. An attacker can provide a malicious S-100 portrayal catalogue containing Lua scripts that execute arbitrary commands with the privileges of the OpenS100 process when a user imports the catalogue and loads a chart.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-749CWE-829

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 5 mentions (2026-02-17); latest day: 1
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-02-17: 5Mentions · 2026-02-22: 1PoC Mentioned / Linked · 2026-02-17: 1Patch / Workaround · 2026-02-17: 1Technical Details · 2026-02-17: 4Technical Details · 2026-02-22: 102-1702-22
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
PoC
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-175
Disclosure3Patch1PoC1
2026-02-221
Disclosure1
Full discourse6 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22208 Remote Code Execution in OpenS100 Viewer via Unrestricted Lua Interpreter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22208

    Post summary

    The text announces CVE-2026-22208, describing a remote code execution vulnerability in OpenS100 Viewer caused by an unrestricted Lua interpreter.

    0000158
    4.0K followersView on X
  • CVE@CVEnew
    PoC

    CVE-2026-22208 OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contain a remote code execution vulnerability via an unrestricted Lua interpreter. The Po… https://www.cve.org/CVERecord?id=CVE-2026-22208

    Post summary

    CVE-2026-22208 is a remote code execution flaw in OpenS100’s viewer due to an unrestricted Lua interpreter, with a Proof of Concept referenced; no exploit code, active exploitation, or patch information is provided.

    00001244
    56.4K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-22208 (CVSS:9.4, CRITICAL) is Awaiting Analysis. OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contain a remote code execution vulnerabili..https://nvd.nist.gov/vuln/detail/CVE-2026-22208 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-22208, a critical remote code execution vulnerability in OpenS100 before commit 753cf29, with CVSS 9.4, but provides no PoC, exploit, patch, or active exploitation details.

    0000048
    171 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL RCE alert! OpenS100 S-100 viewer exposes dangerous Lua methods — attackers can run code via malicious portrayal catalogues. Patch ASAP or block untrusted imports. https://radar.offseq.com/threat/cve-2026-22208-cwe-749-exposed-dangerous-method-or-4594ea65 #OffSeq #CV... https://t.co/8wTgIPE1KX

    Post summary

    OpenS100 S‑100 viewer exposes dangerous Lua methods, enabling remote code execution; users should patch immediately or block untrusted imports to mitigate the vulnerability.

    0000054
    265 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in OpenS100 (CVE-2026-22208) https://vuldb.com/?id.346281

    Post summary

    A new high‑criticality vulnerability (CVE-2026-22208) has been disclosed in OpenS100.

    0000065
    2.1K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-22208: OpenS100 Portrayal Engine Unrest... Maritime security alert: OpenS100's unsandboxed Lua interpreter allows trivial RCE via malicious portrayal catalogues -... https://zerodaysignal.com/vulnerability/CVE-2026-22208 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    OpenS100's unsandboxed Lua interpreter permits trivial remote code execution through malicious portrayal catalogues, with technical details disclosed but no PoC, exploit tool, active exploitation, or patch information provided.

    0000052
    131 followersView on X

Explore more