Junglewise Threat Intelligence

CVE-2026-90492: webgjc web_robot OS command injection in controller_listen

CVE-2026-90492 · Severity: medium · CVSS 6.3 · Published 2026-09-13

Executive brief

webgjc web_robot is a web automation tool that processes case parameters from remote requests. A vulnerability in the case_name argument allows attackers to inject arbitrary operating system commands, potentially leading to complete system compromise. The vulnerability can be exploited remotely without authentication, and the vendor has not responded to early disclosure attempts.

Technical details

The vulnerability is an OS command injection in the controller_listen and controller_recover functions within py/web.py. The case_name argument is processed unsafely, allowing attackers to inject arbitrary shell commands that are executed with the privileges of the web_robot process. The attack is network-reachable and requires no prior authentication. Successful exploitation allows an attacker to execute arbitrary commands on the affected system. No patch is currently available as the vendor has not engaged with the disclosure.

Affected products

  • webgjc web_robot 2.4.0, 2.5.0, 2.8.0

Timeline

  • 2026-09-13: disclosed: Publicly disclosed
  • 2026-09-13: other: Vendor contacted early but did not respond

References