CRITICAL 9.1 NVD
CVE-2026-57499
Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows
Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands on the Liman server. The `ip_address` parameter is embedded directly into a shell command without sanitization, enabling shell escape via single-quote injection. This is fixed in 2.2.2 - 1103.
References
- https://github.com/limanmys/core/security/advisories/GHSA-3jrp-54r2-9g63
- https://github.com/limanmys/core/security/advisories/GHSA-3jrp-54r2-9g63
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-08-27 via NVD.
Risk Timeline
CVE Disclosed2026-08-27 · -1 days ago
Remediation Resources
vulnfeed aggregates 11337 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.