
I discovered CVE-2026-67599, an OS Command Injection in ClearOS's Log Viewer (CVSS 7.2). Authenticated users can chain it to full root via ClearOS's default NOPASSWD sudoers rules. It's EOL but still in the wild, so patch or migrate! Full writeup + PoC: https://lazytitan.ro/clearos
Post summary
ClearOS Log Viewer OS command injection (CVE-2026-67599) remains actively exploited; PoC is available and remediation via patch or migration is urged.


