Executive brief
Cosminexus Component Container is a middleware platform used to run enterprise Java applications. An OS command injection vulnerability in its operation management agent allows unauthenticated remote attackers to execute arbitrary system commands with the privileges of the container process, potentially compromising the entire application server and all hosted applications.
Technical details
A command injection vulnerability exists in the operation management agent component of Cosminexus Component Container. The vulnerability is remotely exploitable over the network without authentication or user interaction required (CVSS vector: AV:N/AC:L/PR:N/UI:N). An attacker can inject arbitrary OS commands that will be executed by the container, leading to complete system compromise. The vulnerability affects multiple major versions (V9 and V11 families) across Windows, Linux, and AIX platforms. Fixed versions are available: Cosminexus Component Container 09-70-28, 09-87-10, 11-00-13, 11-20-10, 11-60-03, and 11-70-03.
Affected products
- Hitachi Cosminexus Component Container V9: 09-00 through 09-00-18, 09-50 through 09-50-22, 09-70 before 09-70-28, 09-80 before 09-80-05, 09-87 before 09-87-10; V11: 11-00 before 11-00-13, 11-10 through 11-10-11, 11-20 before 11-20-10, 11-30 through 11-30-08, 11-40 through 11-40-03, 11-50 through 11-50-03, 11-60 before 11-60-03, 11-70 before 11-70-03
Timeline
- 2026-09-08: disclosed: CVE-2026-71376 published