PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-78797 istoreos CVE debrief

A remote code execution vulnerability exists in iStoreOS istoreos-24.10.7 and prior versions. The issue is related to the task_id in tasks-lib.lua. Defenders should assess exposure, particularly those managing iStoreOS deployments. This vulnerability allows a remote attacker to execute arbitrary code, potentially leading to significant operational impact. It is crucial for defenders to verify the version of iStoreOS and consider implementing compensating controls. The CVE record and source item provide limited information about the vulnerability, so defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Vendor
istoreos
Product
iStoreOS
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-09
Original CVE updated
2026-10-09
Advisory published
2026-10-09
Advisory updated
2026-10-09

Who should care

Defenders managing iStoreOS deployments should assess exposure and verify the version of iStoreOS. Those responsible for securing iStoreOS systems should consider implementing compensating controls and monitoring for potential exploitation attempts.

Why it matters

A remote code execution vulnerability exists in iStoreOS istoreos-24.10.7 and prior versions. Defenders should assess exposure and consider implementing compensating controls.

  • Defenders should verify iStoreOS versions to identify potential exposure.
  • Compensating controls, such as restricting access to the task_id in tasks-lib.lua, may be necessary.
  • Monitoring for potential exploitation attempts is recommended.

Technical summary

The CVE record describes a remote code execution vulnerability in iStoreOS istoreos-24.10.7 and prior versions. The issue is related to the task_id in tasks-lib.lua. This vulnerability allows a remote attacker to execute arbitrary code via the task_id in tasks-lib.lua. The CVE record and source item provide limited information about the vulnerability. Defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. It is crucial for defenders to verify the version of iStoreOS and consider implementing compensating controls. The vulnerability has a high defensive priority, and defenders should assess exposure and consider implementing mitigations.

Defensive priority

High

Recommended defensive actions

  • Assess exposure by reviewing iStoreOS deployments and identifying systems that may be vulnerable.
  • Verify the version of iStoreOS and check if it is istoreos-24.10.7 or prior.
  • Consider implementing compensating controls, such as restricting access to the task_id in tasks-lib.lua.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and source item provide limited information about the vulnerability. The CVE description mentions a remote attacker can execute arbitrary code via the task_id in tasks-lib.lua. However, details about affected versions, exploitation, and remediation are not provided.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-78797 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-78797

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-78797 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78797

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2026-78797

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/78xxx/CVE-2026-78797.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://pastebin.com/zFVpUjxW

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://fw.koolcenter.com/iStoreOS/x86_64_efi/

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://doc.linkease.com/zh/guide/istoreos/install_vmware.html

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/istoreos/istoreos

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/PRISMI-Team/VulnDisclos/blob/main/Routers/iStoreOS/authorized-rce.md

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.