CVE-2026-23515Disclosure(signalk / signal_k_server)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch signalk signal_k_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server when the set-system-time plugin is enabled. Unauthenticated users can also exploit this vulnerability if security is disabled on the Signal K server. This occurs due to unsafe construction of shell commands when processing navigation.datetime values received via WebSocket delta messages. This vulnerability is fixed in 1.5.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • signal_k_server

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-02-03); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
signal_k_server

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-02-02: 2Mentions · 2026-02-03: 3Mentions · 2026-03-02: 1Patch / Workaround · 2026-02-03: 2Technical Details · 2026-02-02: 2Technical Details · 2026-02-03: 302-0202-0303-02
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-022
Disclosure2
2026-02-033
Disclosure1Patch2
2026-03-021
General1
Full discourse6 posts
  • David@DavidMarquet19
    General

    📌 Top CVEs recientes (CVSS>=7.0): 1. 🛡️ CVE-2026-25221 (CVSS: 8.1) 2. ⚠️ CVE-2026-25134 (CVSS: 8.8) 3. ⚠️ CVE-2026-23515 (CVSS: 9.9) 4. 🕷️ CVE-2025-13096 (CVSS: 7.1) 5. ⚠️ CVE-2026-22229 (CVSS: 7.2) #CyberSecurity #CVE #Infosec

    Post summary

    The text lists several recent CVEs with high CVSS scores but provides no additional details on exploitation, patches, or technical specifics.

    0000076
    167 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    The Signal K Set-System-Time plugin has an RCE vulnerability via command injection (CVE-2026-23515). This affects systems using the plugin. Update to 1.5.0. #SignalK #RCE #CommandInjection https://www.pulsepatch.io/posts/cve-2026-23515-signal-k-set-system-time-rce-command-injection

    Post summary

    The post alerts users to an RCE vulnerability (CVE-2026-23515) in the Signal K Set‑System‑Time plugin and recommends updating to version 1.5.0 to remediate the issue.

    0000027
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23515 Command Injection Vulnerability in Signal K Server Prior ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23515 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces CVE-2026-23515, a command injection vulnerability in Signal K Server, and links to a Vulmon page for further details while encouraging vulnerability scanning.

    0000052
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-23515: CRITICAL] Signal K Server <1.5.0 allows authenticated users to execute shell commands. Unauthenticated users can exploit this if security is disabled. Update to 1.5.0 to fix this.#cve,CVE-2026-23515,#cybersecurity https://cvefind.com/CVE-2026-23515

    Post summary

    Signal K Server <1.5.0 allows authenticated users to execute shell commands and unauthenticated users when security is disabled; updating to 1.5.0 fixes the vulnerability.

    0000081
    583 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23515 Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write … https://www.cve.org/CVERecord?id=CVE-2026-23515

    Post summary

    The note announces a command injection flaw in Signal K Server (pre‑1.5.0) with no additional exploit, patch, or active‑use information.

    00000167
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-23515: RCE - Command Injection in Signa... Maritime mayhem: WebSocket delta messages in set-system-time plugin allow shell command injection via navigation.dateti... https://zerodaysignal.com/vulnerability/CVE-2026-23515 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-23515, describing a remote code execution vulnerability caused by command injection in Signa’s set‑system‑time plugin via WebSocket delta messages. No PoC, exploit tool, active exploitation, patch, or debunking information is provided.

    0000050
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsignalksignal_k_server---

Explore more