CVE-2026-35582Disclosure(nsa / emissary)

HIGHCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch nsa emissary systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolates temporary file paths into a /bin/sh -c shell command string without any escaping or input validation. The IN_FILE_ENDING and OUT_FILE_ENDING configuration keys flow directly into these paths, allowing a place author who can write or modify a .cfg file to inject arbitrary shell metacharacters that execute OS commands in the JVM process's security context. The framework already sanitizes placeName via an allowlist before embedding it in the same shell string, but applies no equivalent sanitization to file ending values. No runtime privileges beyond place configuration authorship, and no API or network access, are required to exploit this vulnerability. This is a framework-level defect with no safe mitigation available to downstream implementors, as Executrix provides neither escaping nor documented preconditions against metacharacters in file ending inputs. This issue has been fixed in version 8.43.0.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-116

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • emissary

Threat summary

  • Active exploitation appears in 1 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
emissary

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-18: 3Exploit Tool / Code · 2026-04-18: 1Active Exploitation · 2026-04-18: 1Patch / Workaround · 2026-04-18: 1Technical Details · 2026-04-18: 304-18
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-35582 Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolat… https://www.cve.org/CVERecord?id=CVE-2026-35582

    Post summary

    The post announces that CVE‑2026‑35582 enables OS command injection in Emissary’s Execute.getCommand() for versions 8.42.0 and older, providing basic technical details but no exploitation or mitigation information.

    00000106
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35582 OS Command Injection in Emissary Versions 8.42.0 and Below via Configura... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35582 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A vulnerability announcement for CVE-2026-35582 reporting an OS command injection in Emissary versions 8.42.0 and earlier; no PoC, exploit code, patch, or active exploitation details are included.

    0000041
    4.0K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Emissary CVE-2026-35582 is under active exploitation—attackers can inject OS commands via Executrix. CVSS 9.2. This bypasses most defenses—assume full compromise. Patch now to prevent further breaches. #NerdieNews #CyberSecurity #InfoSec #ZeroDay #Microsoft https://t.co/djmDt5522d

    Post summary

    CVE-2026-35582 is being actively exploited via OS command injection through Executrix, and users are urged to apply the available patch to halt further breaches.

    0000067
    55 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnsaemissary---

Explore more