CVE-2026-66148

An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges.

  • Published Aug 11, 2026
  • CVSS 6.3 medium
  • 1.1% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-66148 at the National Vulnerability Database