PatchDayAlert

CVE

CVE-2026-49481

0field notes · 1digest CVSS 9.6

The verdict

UpSnap, the wake-on-LAN web app, has an OS command injection bug in its device management. The IP and MAC fields in wake/shutdown command templates aren't sanitized, so a low-privileged user who can create or edit devices can inject arbitrary shell commands. Those commands run as the UpSnap service account on the host OS.

Patch urgency · Patch this week


Daily digests