CVE-2026-4851Disclosure(casiano / grid\)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine provides Remote Procedure Calls (RPC) over SSH for Perl. The client connects to remote hosts to execute code on them. A compromised or malicious remote host can execute arbitrary code back on the client through unsafe deserialization in the RPC protocol. read_operation() in lib/GRID/Machine/Message.pm deserialises values from the remote side using eval() $arg .= '$VAR1'; my $val = eval "no strict; $arg"; # line 40-41 $arg is raw bytes from the protocol pipe. A compromised remote host can embed arbitrary perl in the Dumper-formatted response: $VAR1 = do { system("..."); }; This executes on the client silently on every RPC call, as the return values remain correct. This functionality is by design but the trust requirement for the remote host is not documented in the distribution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-95CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grid\

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-29)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
grid\

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-28: 1Mentions · 2026-03-29: 2Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 103-2803-29
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-281
Disclosure1
2026-03-292
Disclosure1General1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2014-125112: Plack::Middleware::Session::Cookie versions through 0.21 allows remote code execution https://www.openwall.com/lists/oss-security/2026/03/26/2 CVE-2026-4851: GRID::Machine remote-to-local code execution https://www.openwall.com/lists/oss-security/2026/03/26/6

    Post summary

    The text announces two Perl CPAN modules with remote code execution vulnerabilities, giving brief technical details and linking to advisory threads, but no PoC, exploit code, or patch information.

    00060297
    4.4K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4851 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4851 #CVE-2026-4851 #CVE #CyberSecurity #InfoSec https://t.co/VUex2r3KSk

    Post summary

    The tweet simply announces CVE-2026-4851 with no further technical detail or actionable information.

    0001029
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4851 - GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization Intel Report: https://ift.tt/Csb8QWL

    Post summary

    The tweet announces CVE-2026-4851, noting unsafe deserialization in Grid::Machine Perl versions, but does not share PoC, exploit code, or patch information.

    0000023
    280 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcasianogrid\\--

Explore more