Junglewise Threat Intelligence

CVE-2026-90822: FatPipe MPVPN, WARP, and IPVPN OS command injection in xtremed

CVE-2026-90822 · Severity: critical · CVSS 9.8 · Published 2026-09-17

Technologies: Fatpipe WARP, Fatpipe IPVPN. Vendors: Fatpipe.

Executive brief

FatPipe MPVPN, WARP, and IPVPN are WAN optimization and SD-WAN appliances used to manage multi-site network connectivity and performance. A critical unauthenticated remote code execution vulnerability in firmware version 10.1.2r60p100 allows attackers who reach the management interface to inject arbitrary shell commands that execute with root privileges, potentially leading to complete compromise of the appliance and the networks it protects.

Technical details

The vulnerability is an OS command injection flaw in the xtremed daemon, accessible via the AuthFormServlet endpoint on the management interface. An unauthenticated remote attacker can submit crafted input that is processed by a shell without proper sanitization, allowing arbitrary command execution as root. The management interface is disabled by default but becomes reachable once explicitly enabled by administrators. Exploitation requires network access to the management interface; however, no authentication is required. FatPipe recommends restricting management access to trusted networks using firewall ACLs and upgrading from the end-of-life firmware version 10.1.2r60p100 to a current supported release.

Affected products

  • FatPipe MPVPN 10.1.2r60p100
  • FatPipe WARP 10.1.2r60p100
  • FatPipe IPVPN 10.1.2r60p100

Timeline

  • 2026-09-17: disclosed

References

Related threats