CVE-2026-2333

Severity CVSS v4.0:
CRITICAL
Type:
CWE-77 Command Injection
Publication date:
20/02/2026
Last modified:
26/02/2026

Description

Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command Injection via a crafted network request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:owlcyberdefense:opds-talon:2.2.0.4:*:*:*:*:*:*:*
cpe:2.3:h:owlcyberdefense:opds-100:-:*:*:*:*:*:*:*
cpe:2.3:o:owlcyberdefense:opds-talon:2.2.0.4:*:*:*:*:*:*:*
cpe:2.3:h:owlcyberdefense:opds-1000:-:*:*:*:*:*:*:*