Skip to main content
HIGH

CVE-2026-92580

CVSS v3

8.8

HIGH

EPSS Score

1.1 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync ...` with a plain str_replace and no escaping, so a single quote in the password breaks out of the quoted word and injects arbitrary shell. The password is written through the admin-only endpoint objects/pluginAddDataObject.json.php, whose only CSRF defense (isU

Technical details

CVSS v3 Vector
3.1
Published
2026-09-16
Last Modified
2026-09-16

Frequently asked questions

What is CVE-2026-92580?

In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync ...` with a plain str_replace and no escaping, so a single quote in the password breaks out of the quoted word and injects arbitrary shell. The password is written through the admin-only endpoint objects/pluginAddDataObject.json.php, whose only CSRF defense (isU

Is CVE-2026-92580 actively exploited?

Active exploitation of CVE-2026-92580 has not been confirmed. The EPSS score is 1.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-92580?

CVE-2026-92580 has a CVSS v3 base score of 8.8 (HIGH severity), with vector string 3.1.

Is CVE-2026-92580 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key