Junglewise Threat Intelligence

CVE-2026-71377: Hitachi Cosminexus Component Container command argument injection

CVE-2026-71377 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Technologies: Hitachi Cosminexus Component Container. Vendors: Hitachi.

Executive brief

Hitachi Cosminexus Component Container, a middleware platform used to manage enterprise applications, contains a command argument injection vulnerability in its operation management agent. An attacker with network access can inject malicious arguments into system commands, leading to remote code execution without authentication. This could allow complete compromise of the server and all applications it hosts.

Technical details

A command argument injection vulnerability exists in the operation management agent of Cosminexus Component Container. The vulnerability is triggered via network-accessible interfaces, requires no authentication or user interaction, and allows attackers to inject arbitrary command arguments. An attacker can achieve code execution with high impact on confidentiality, integrity, and availability (CVSS 9.8). Patches are available: Cosminexus Component Container versions 09-70-28, 09-87-10, 11-20-10, 11-60-03, and 11-70-03 address this issue; affected installations should upgrade immediately.

Affected products

  • Hitachi Cosminexus Component Container V11: 11-00-0 through 11-70-02 (multiple branches); V9: 09-00-0 through 09-87-09 (multiple branches)

Timeline

  • 2026-09-08: disclosed

References

Related threats