CVE-2026-28279Disclosure(jmpsec / osctrl)

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jmpsec osctrl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `osctrl-admin` environment configuration. An authenticated administrator can inject arbitrary shell commands via the hostname parameter when creating or editing environments. These commands are embedded into enrollment one-liner scripts generated using Go's `text/template` package (which does not perform shell escaping) and execute on every endpoint that enrolls using the compromised environment. An attacker with administrator access can achieve remote code execution on every endpoint that enrolls using the compromised environment. Commands execute as root/SYSTEM (the privilege level used for osquery enrollment) before osquery is installed, leaving no agent-level audit trail. This enables backdoor installation, credential exfiltration, and full endpoint compromise. This is fixed in osctrl `v0.5.0`. As a workaround, restrict osctrl administrator access to trusted personnel, review existing environment configurations for suspicious hostnames, and/or monitor enrollment scripts for unexpected commands.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • osctrl

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-28); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
osctrl

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-02-27: 2Mentions · 2026-02-28: 3Mentions · 2026-03-03: 1Patch / Workaround · 2026-02-28: 1Technical Details · 2026-02-27: 2Technical Details · 2026-02-28: 3Technical Details · 2026-03-03: 102-2702-2803-03
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-272
Disclosure2
2026-02-283
Disclosure2Patch1
2026-03-031
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28279 (CVSS:7.3, HIGH) is Analyzed. osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `o..https://nvd.nist.gov/vuln/detail/CVE-2026-28279 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-28279, an OS command injection vulnerability in osctrl before v0.5.0, with a CVSS score of 7.3, but provides no PoC, exploit, or patch details.

    0000035
    173 followersView on X
  • Peerdev & Code learnings@Peerdev_
    Patch

    CVE-2026-28279 : injection de commandes dans osctrl‑admin. Mettez à jour vers 0.5.0 et filtrez les hostnames. Détails 👉 https://dev.to/cverports/cve-2026-28279-osctrl-admin-enrollment-script-command-injection-3bhg #Sécurité #DevOps

    Post summary

    The post warns of a command injection flaw in osctrl‑admin and advises updating to version 0.5.0 and filtering hostnames, without providing a PoC or exploit details.

    0000035
    5 followersView on X
  • Jason@flarestartcom
    Disclosure

    CVE-2026-28279: osctrl-admin Enrollment Script Command Injection via http://Dev.to https://flarestart.com/article/cve-2026-28279-osctrl-admin-enrollment-script-command-injection-20260228 #DevNews #Security #Tutorial https://t.co/3pAzERgpt5

    Post summary

    The tweet announces CVE‑2026‑28279, a command injection vulnerability in osctrl‑admin, and links to an article, but provides no exploit code, active exploitation evidence, or patch details.

    0000042
    14 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-28279: osctrl-admin Enrollment Script Command Injection A critical command injection vulnerability exists in the osctrl-admin component of the osctrl osquery management platform. The vulnerability allows authenticated administrators to inject... https://cvereports.com/reports/CVE-2026-28279

    Post summary

    The report discloses a critical command injection flaw in osctrl-admin that lets authenticated administrators execute arbitrary commands.

    0000048
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28279 osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `osctrl-admin` environment configuration. An aut… https://www.cve.org/CVERecord?id=CVE-2026-28279

    Post summary

    A new OS command injection vulnerability has been disclosed for osctrl-admin prior to version 0.5.0, with no evidence of exploitation or mitigation in the provided text.

    00000134
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28279 OS Command Injection in osctrl Admin Environment Configuration Before v0.5.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28279

    Post summary

    A new OS Command Injection vulnerability in osctrl Admin Environment Configuration before version 0.5.0 has been disclosed.

    0000045
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjmpsecosctrl---

Explore more