Description
A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipulation of the argument target/params leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 3d52f65803a2716bff14d938352c6fef45b0cfb6. A patch should be applied to remediate this issue. This issue got fixed with a silent patch.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: 2.2% Low
KEV: No
Impact: Remote Command Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the nmap_newscan function of functions_nmap.py in WebMap. By manipulating the target/params argument an attacker can inject arbitrary OS commands. This allows remote execution of commands on the server hosting WebMap, compromising confidentiality, integrity, and availability of the affected system.

Affected Systems

SabyasachiRana WebMap, any release up to commit 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25, all users of the New Nmap Scan Handler component.

Risk and Exploitability

The CVSS base score of 6.9 indicates a moderate severity threat. The EPSS score is 1%, indicating a low but nonzero probability of exploitation. The vulnerability is disclosed publicly and can be leveraged remotely. The attack can be executed over the network by providing crafted parameters to the Nmap scan endpoint without authentication, assuming no additional controls are in place. The vulnerability is not yet listed in CISA's KEV catalog.

Generated by OpenCVE AI on September 17, 2026 at 18:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch corresponding to commit 3d52f65803a2716bff14d938352c6fef45b0cfb6 to the affected WebMap installation.
  • If an immediate patch is unavailable, harden the Nmap scan input by validating or sanitizing the target/params argument to reject any characters that could spawn shell commands.
  • Restrict access to the Nmap scan functionality or disable it until the patch is applied.
  • Monitor logs for anomalous command execution patterns and network traffic associated with the scan endpoint.

Generated by OpenCVE AI on September 17, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipulation of the argument target/params leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 3d52f65803a2716bff14d938352c6fef45b0cfb6. A patch should be applied to remediate this issue. This issue got fixed with a silent patch.
Title SabyasachiRana WebMap New Nmap Scan functions_nmap.py nmap_newscan os command injection
First Time appeared Sabyasachirana
Sabyasachirana webmap
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:sabyasachirana:webmap:*:*:*:*:*:*:*:*
Vendors & Products Sabyasachirana
Sabyasachirana webmap
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 8.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Sabyasachirana Webmap
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-02T15:52:03.627Z

Reserved: 2026-09-14T05:06:39.005Z

Link: CVE-2026-90843

cve-icon Vulnrichment

Updated: 2026-09-16T16:50:52.502Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T01:16:53.627

Modified: 2026-09-16T17:18:18.230

Link: CVE-2026-90843

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')