CVE-2026-30303 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 27, 2026
Axon Code - OS Command Injection
Published: March 27, 2026Updated: March 27, 2026Remote Exploitable
Overview
Axon Code contains an OS command injection caused by improper command parsing on Windows in the auto-approval module, letting attackers execute arbitrary commands remotely, exploit requires crafted command input.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Attackers can execute arbitrary commands remotely, potentially leading to full system compromise.
Mitigation
Update to the latest version with fixed command parsing or apply patches addressing Windows CMD escape sequence handling.
Related Resources
Details
- CVE ID
- CVE-2026-30303
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- command_injection
- Status
- new
CWE
- CWE-78
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H