Junglewise Threat Intelligence

CVE-2026-15496: SonicCloudOrg sonic-agent OS command injection in Groovy Script Handler

CVE-2026-15496 · Severity: medium · CVSS 6.3 · Published 2026-07-12

Technologies: SonicCloudOrg Sonic-Agent. Vendors: SonicCloudOrg.

Executive brief

SonicCloudOrg sonic-agent is a component used for managing and executing tests within the Sonic cloud testing platform. A security vulnerability in its Groovy script handling allows an attacker to execute unauthorized operating system commands on the server. This could lead to a complete system compromise, unauthorized data access, or service disruption. The product is no longer supported by the vendor, and no official patch is expected.

Technical details

An OS command injection vulnerability exists in SonicCloudOrg sonic-agent versions up to 2.7.2. The flaw is located within the evalIsFailed function in the GroovyScriptImpl.java file of the Groovy Script Handler component. The vulnerability stems from improper neutralization of special elements used in an OS command (CWE-78) when processing Groovy scripts. A remote attacker with low privileges can exploit this by submitting manipulated input that is executed as a system command. Public exploit code is available, but the vendor has indicated the product is no longer supported, meaning no official patch will be released.

Affected products

  • SonicCloudOrg sonic-agent up to 2.7.2

Timeline

  • 2026-07-12: advisory: NVD publication date
  • 2026-07-12: disclosed: Public disclosure of the vulnerability and exploit code

References

Related threats