{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/clearos-7.9/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-67599"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ClearOS (7.9)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","privilege-escalation","webserver"],"_cs_type":"advisory","_cs_vendors":["ClearFoundation"],"content_html":"\u003cp\u003eClearOS 7.9 contains a critical OS command injection vulnerability (CVE-2026-67599) located within the Log Viewer component. The vulnerability resides in the File.php script, which fails to properly sanitize input provided through the 'filter' parameter before interpolating it into a shell command. An authenticated attacker can exploit this flaw to execute arbitrary system commands running under the context of the webconfig user.\u003c/p\u003e\n\u003cp\u003eOf particular concern to defenders is the system's default configuration, which grants the webconfig user extensive NOPASSWD sudo privileges. This misconfiguration allows an attacker to transition from successful command injection to full root-level compromise of the ClearOS system without requiring further authentication or password entry. The vulnerability is specific to ClearOS 7.9 running on CentOS 7, and its impact is compounded by the high-privilege execution environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full unauthorized command execution on the target ClearOS appliance. Because the webconfig user possesses NOPASSWD sudo rights, attackers can immediately pivot to root-level access. This allows for total system control, including data exfiltration, installation of persistent backdoors, and the potential for lateral movement within the network from the compromised appliance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and restrict access to the ClearOS web management interface to trusted administrative network segments.\u003c/li\u003e\n\u003cli\u003eReview and remove NOPASSWD sudo privileges for the webconfig user in /etc/sudoers to prevent immediate privilege escalation.\u003c/li\u003e\n\u003cli\u003eApply security patches provided by ClearFoundation for CVE-2026-67599 as soon as they become available.\u003c/li\u003e\n\u003cli\u003eAudit web access logs for anomalous POST requests directed at the Log Viewer component containing shell metacharacters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T20:48:50Z","date_published":"2026-08-03T20:48:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-clearos-command-injection/","summary":"ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands as the webconfig user, with subsequent escalation to root.","title":"OS Command Injection in ClearOS Log Viewer","url":"https://feed.craftedsignal.io/briefs/2026-08-clearos-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - ClearOS (7.9)","version":"https://jsonfeed.org/version/1.1"}