Executive brief
HGiga iSherlock, a security appliance used for email auditing and spam filtering, contains a critical vulnerability. An attacker can execute unauthorized commands on the server, potentially leading to a complete system takeover, data theft, or disruption of email services. This issue affects several product variants including MailSherlock, SpamSherlock, and AuditSherlock.
Technical details
An OS command injection vulnerability (CWE-78) exists in HGiga iSherlock versions 4.5 and 5.5. The flaw allows unauthenticated attackers with local access to inject and execute arbitrary operating system commands on the underlying server. While the CVSS vector indicates network accessibility (AV:N), the description specifies local attackers; in either case, the lack of authentication requirements makes this highly critical. The vulnerability impacts the iSherlock-base and iSherlock-audit packages. Users should update iSherlock-base to version 476 or later and iSherlock-audit to version 261 or later to mitigate this risk.
Affected products
- HGiga (桓基科技) iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) 4.5 and 5.5 (iSherlock-base before 476, iSherlock-audit before 261)
Timeline
- 2026-04-16: disclosed: Initial disclosure by TWCERT/CC
- 2026-04-16: advisory: NVD publication date