← Vulnerability feed

Vulnerability record · CVE-2025-59783 · published 4 March 2026

CVE-2025-59783: 2n access commander os command injection vulnerability

22n · Access Commander

API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injection. This vulnerability can only be exploited after authenticating with administrator privileges.

8.8 CVSS 4.0 High EPSS 0.86% · top 43.1% CWE-78 · OS command injection
8.8CVSS 4.0 base score
0.86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injection. This vulnerability can only be exploited after authenticating with administrator privileges.

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-59783 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-472552n access commander vulnerabilityIn 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which could allow for arbitrary code …EPSS 0.10%7.2CVE-2024-472542n access commander vulnerabilityIn 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability could allow an attacker to escalat…EPSS 0.35%7.2CVE-2024-472532n access commander path traversal vulnerabilityIn 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write fil…EPSS 0.95%6.9CVE-2025-597842n access commander vulnerability2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prio…EPSS 0.29%6.0CVE-2025-597862n access commander insufficient session expiration vulnerability2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in…EPSS 0.25%5.3CVE-2025-597852n access commander vulnerabilityImproper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encrypt…EPSS 0.19%5.3CVE-2025-597872n access commander vulnerability2N Access Commander application version 3.4.2 and prior returns HTTP 500 Internal Server Error responses when receiving malformed or manipulated requ…EPSS 0.19%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed

Source: NIST National Vulnerability Database (record CVE-2025-59783), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.