logo

Critical Command Injection Flaw Hits upKeeper Instant Privilege Access

ID: 7f75129a-a8b2-5304-820c-5e3816b98a6e

STIX ID: report--7f75129a-a8b2-5304-820c-5e3816b98a6e

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-17

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical command-injection vulnerability (CVE-2026-2449, CVSS 9.1) in upKeeper Instant Privilege allows manipulation of internal message delimiters to inject commands into the client service, enabling low-privileged users to execute arbitrary commands as LocalSystem. The flaw affects all versions through 1.5.0 and has been fixed in version 1.6.0.4576 (released March 5, 2026); administrators are urged to apply the mandatory update to prevent unauthorized privilege escalation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.