#VU125045 Command injection in emissary - CVE-2026-35581
Published: April 7, 2026
emissary
National Security Agency
Description
The vulnerability allows a remote user to execute arbitrary commands.
The vulnerability exists due to command injection in the Executrix utility class when processing configuration-derived PLACE_NAME values in shell commands. A remote privileged user can supply a specially crafted PLACE_NAME value to execute arbitrary commands.
Exploitation requires control over configuration values, such as through administrative access or a compromised configuration source.