CVE-2026-56415
Stonefly Storage Concentrator, Storage Concentrator Virtual Machine
Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is processed without adequate input sanitization, resulting in arbitrary command execution with root-level privileges on the underlying system.
- CVSS
- 10
- EPSS
- 3.07% 86.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.01