Description
CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.
Published: 2026-08-26
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Immediate patch
AI Analysis

Impact

A code injection flaw in CorvusSKK permits an attacker to embed and execute malicious code within the application’s environment. This vulnerability is classified as CWE‑94 and can lead to complete compromise of confidentiality, integrity, and availability if exploited, effectively providing remote code execution capabilities.

Affected Systems

The vulnerability affects the CorvusSKK application produced by SASAKI Nobuyuki. No specific product versions are detailed in the advisory, so all current installations are considered potentially exposed until confirmed patched.

Risk and Exploitability

The CVSS score of 8.4 signals a high‑severity risk. No EPSS data is available, and the issue is not currently listed in CISA KEV. Exploitation likely requires access to input data that the application processes unsafely; once triggered, arbitrary code can run in the application’s context. Given the severe impact and lack of known mitigation, unpatched systems face a substantial risk of compromise.

Generated by OpenCVE AI on August 26, 2026 at 07:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update CorvusSKK to release 3.3.4 to remove the injection flaw
  • If an upgrade is not immediately feasible, reconfigure the application to reject or escape any user‑supplied input that could be interpreted as code, and disable optional code execution modules if possible
  • Enable system and application logging to detect unexpected process creation or execution, and configure alerts for anomalous activity

Generated by OpenCVE AI on August 26, 2026 at 07:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Sasaki Nobuyuki
Sasaki Nobuyuki corvusskk
Vendors & Products Sasaki Nobuyuki
Sasaki Nobuyuki corvusskk

Wed, 26 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title CorvusSKK Code Injection Allowing Arbitrary Execution

Wed, 26 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Description CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.
Weaknesses CWE-94
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Sasaki Nobuyuki Corvusskk
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-26T14:09:06.066Z

Reserved: 2026-08-19T05:08:38.977Z

Link: CVE-2026-76148

cve-icon Vulnrichment

Updated: 2026-08-26T14:09:00.160Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T05:18:18.953

Modified: 2026-08-28T16:09:10.947

Link: CVE-2026-76148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:33:55Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')