Junglewise Threat Intelligence

CVE-2026-11408: vertex-app vertex OS command injection in Log Viewer Endpoint

CVE-2026-11408 · Severity: medium · CVSS 6.3 · Published 2026-06-06

Executive brief

Vertex, a management tool for media and download automation, contains a security flaw in its log viewing feature. An attacker with basic user access can trick the system into executing unauthorized commands on the underlying server. This could allow an attacker to take control of the application, access sensitive files, or disrupt operations.

Technical details

An OS command injection vulnerability exists in vertex-app vertex up to version 2026.02.12 within the Log Viewer Endpoint. The root cause is located in 'app/model/LogMod.js', where the 'type' parameter from 'req.query' is passed directly into the 'execSync()' function without proper sanitization or validation. A remote attacker with low privileges can exploit this by sending a crafted GET request to the '/api/log/get' route containing shell metacharacters (e.g., $(command)). Successful exploitation allows for arbitrary command execution on the host operating system. Additionally, the lack of CSRF protection on this endpoint may allow an attacker to trigger the vulnerability via a victim administrator's browser. A patch has been released in commit 805d82e7100d49b79b3beb1b9420e8e458987198.

Affected products

  • vertex-app vertex up to 2026.02.12

Timeline

  • 2026-05-03: disclosed: Initial security report and PoC video created
  • 2026-06-06: advisory: NVD publication date
  • 2026-06-06: patched: Patch commit 805d82e identified

References