HIGH
ClearFoundation
CVE published 2026-08-03
CVE-2026-67599
CVE-2026-67599 is an OS command injection vulnerability in ClearOS 7.9's Log Viewer component. Authenticated attackers can execute arbitrary commands by submitting unsanitized input through the filter parameter. The vulnerability allows immediate escalation to root due to extensive NOPASSWD sudo privileges granted to the webconfig user by default. This vulnerability has a high CVSS score of 8.6 and is cla [truncated]