Junglewise Threat Intelligence

CVE-2026-57499: Liman OS command injection in log rotation configuration

CVE-2026-57499 · Severity: critical · CVSS 9.1 · Published 2026-08-27

Executive brief

Liman is open source server management software used to manage and monitor multiple systems. An authenticated administrator can inject arbitrary operating system commands through the log rotation configuration endpoint, gaining full control of the Liman server with the privileges of the underlying service account. This allows a compromised or malicious admin to execute commands, modify files, and potentially pivot to other systems managed by Liman.

Technical details

The vulnerability is an OS command injection (CWE-78) in the LogRotationController's saveConfiguration() endpoint. The ip_address parameter is validated only for minimum length (no IP format validation) and is directly embedded into a shell command via str_replace() without any escaping. An attacker can break out of the enclosing single-quote context using a single-quote character, injecting arbitrary shell commands. The vulnerable code path flows through app/System/Command.php's unsafe :text: placeholder substitution which performs raw string replacement with no shell escaping. Authentication as an administrator is required, but the endpoint is accessible via POST /api/settings/advanced/log_rotation. The attacker gains code execution as the liman-system service user. This is fixed in version 2.2.2 - 1103.

Affected products

  • Liman Liman prior to 2.2.2 - 1103

Timeline

  • 2026-06-22: disclosed: GitHub advisory GHSA-3jrp-54r2-9g63 published
  • 2026-06-22: patched: Fixed in version 2.2.2 - 1103

References