CVE-2026-94490 | OctoPrint 1.0.0 Command API system.py executeSystemCommand command os command injection
A vulnerability was found in OctoPrint 1.0.0. It has been classified as problematic. Affected by this issue is the function executeSystemCommand of the file src/octoprint/server/api/system.py of the component Command API. Performing a manipulation of the argument command results in os command injection.
This vulnerability is cataloged as CVE-2026-94490. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More