CVE-2026-59561Disclosure

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-08-24); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-24: 2Mentions · 2026-08-27: 1Mentions · 2026-09-11: 1Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-09-11: 1Technical Details · 2026-08-24: 2Technical Details · 2026-08-27: 1Technical Details · 2026-09-11: 108-2408-2709-11
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-242
Disclosure2
2026-08-271
Patch1
2026-09-111
Patch1
Full discourse4 posts
  • nano@nano357
    Patch

    ⚠️サクラエディタに脆弱性 「ターミナルを起動」機能に、任意のOSコマンドが実行されるおそれのある脆弱性(CVE-2026-59561)が確認されています。 対象:v2.4.3未満 対策:v2.4.3以降へアップデート 詳細はJVNをご確認ください。 本当の問題は上記じゃない件の記事👇️ https://www.2cobo2.jp/archives/2914

    Post summary

    CVE-2026-59561 in Sakuha Editor allows arbitrary OS command execution through the terminal launch feature; users should update to version 2.4.3 or later to mitigate the issue.

    00132954
    2.0K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    サクラエディタにOSコマンドインジェクションの脆弱性、CVE-2026-59561 v2.4.3へ更新を https://rocket-boys.co.jp/security-measures-lab/sakura-editor-os-command-injection-cve-2026-59561/ #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性

    Post summary

    The post announces that Sakura Editor suffers from an OS command injection flaw (CVE-2026-59561) and that users should update to version 2.4.3, with a link for further details.

    00011222
    554 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-59561 Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted… https://www.cve.org/CVERecord?id=CVE-2026-59561

    Post summary

    The message announces the disclosure of CVE-2026-59561, namely an OS command injection flaw in Sakura Editor, without providing any exploit code, PoC, or mitigation details.

    00010876
    58.0K followersView on X
  • ot2sy39@ot2sy39
    Disclosure

    サクラエディタにOSコマンドインジェクションですって。エディタにCWE-78って……。 / CVE-2026-59561 https://jvn.jp/jp/JVN74538868/index.html

    Post summary

    The text announces an OS command injection vulnerability (CWE‑78) in Sakura Editor, identified as CVE‑2026‑59561, and directs readers to a JVN entry for additional information.

    00000115
    352 followersView on X

Explore more