Junglewise Threat Intelligence

CVE-2026-10550: elunez eladmin command injection in Application Deployment Module

CVE-2026-10550 · Severity: medium · CVSS 6.3 · Published 2026-06-02

Executive brief

elunez eladmin is a management system used for administrative tasks and application deployment. A security flaw in its deployment module allows users with low-level permissions to inject malicious commands into configuration fields. If an administrator or automated process later triggers a deployment using these poisoned settings, the attacker's commands will execute on the server, potentially leading to a full system takeover and unauthorized access to sensitive data.

Technical details

A second-order stored command injection vulnerability exists in elunez eladmin up to version 2.7 within the Application Deployment Module. The vulnerability stems from insufficient input validation in App.java and AppServiceImpl.java, where fields like uploadPath, deployPath, and backupPath only undergo weak prefix checks that can be bypassed using newline characters (\n) or command substitution ($()). These malicious payloads are stored in the database and later executed via string concatenation in DeployServiceImpl.deployApp() using ExecuteShellUtil.execute(). Because the system utilizes JSch ChannelShell for direct shell interpretation, the injected commands run with high privileges when a deployment is triggered. As of the advisory date, the project maintainers have not yet responded to the issue report.

Affected products

  • elunez eladmin up to 2.7

Timeline

  • 2026-05-13: disclosed: Issue reported on GitHub repository
  • 2026-06-02: advisory: CVE published to NVD dataset

References

Related threats