Junglewise Threat Intelligence

CVE-2026-78211: 4MOSAn GCB Doctor OS command injection via ADOdb test page

CVE-2026-78211 · Severity: critical · CVSS 9.8 · Published 2026-08-24

Executive brief

4MOSAn GCB Doctor is a security management tool used to monitor and manage infrastructure systems. The vulnerability allows unauthenticated attackers on the network to execute arbitrary operating system commands on the server by exploiting an unremoved test page, potentially compromising the entire monitored infrastructure and enabling unauthorized access, data theft, or system sabotage.

Technical details

The vulnerability is an OS command injection flaw in 4MOSAn GCB Doctor versions prior to 20260621. The root cause is an unremoved ADOdb test page parameter that accepts unsanitized user input without proper validation or escaping. Unauthenticated remote attackers can exploit this by crafting malicious commands via network access; no authentication or user interaction is required. Successful exploitation allows arbitrary system command execution with the privileges of the application process, potentially providing full system compromise. The fix is available: upgrade to version 20260621 or later and perform the FreeBSD-GCB Management Center security upgrade.

Affected products

  • 4MOSAn Security Technology GCB Doctor before 20260621

Timeline

  • 2026-08-24: disclosed

References

Related threats