CWE-77Class16 in KEV

Improper Neutralization of Special Elements used in a Command ('Command Injection')

Draft in the CWE catalog · 1,898 CVEs mapped

1,898
CVEs mapped
16
In KEV
7.0
Median CVSS
What it is

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Recent examples
8.8cvss
CVE-2026-86427

LibreNMS before 26.8.0 Argument Injection via graph_title

LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of double-quote escaping. Attackers can inject DEF and LINE arguments to read RRD files from unauthorized devices, or use newline injection to execute arbitrary rrdtool commands, bypassing per-device authorization checks.

HIGHno explanation yet
epss
9.9cvss
CVE-2026-86299

Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection

A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched remotely. The exploit is now public and may be used.

CRITICALno explanation yet
epss
8.3cvss
CVE-2026-86295

D-Link DIR-895L udhcpcd serverpacket.c sendACK command injection

A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.

HIGHno explanation yet
epss
The record
Technical detail
CWE ID
CWE-77
Abstraction
Class
Structure
Simple
Status
Draft
References (3)