CVE-2026-67599 is an OS command injection vulnerability in ClearOS 7.9 affecting the Log Viewer component. The flaw is caused by unsanitized user-controlled input supplied through the filter parameter being interpolated directly into a shell command in File.php. An authenticated attacker can inject command substitution payloads into this parameter to execute arbitrary operating system commands in the context of the webconfig user. Because the webconfig user is granted extensive NOPASSWD sudo privileges by default, successful exploitation can be chained directly into privilege escalation to root.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit repo containing one Python proof-of-concept script and a README documenting CVE-2026-67599, an authenticated OS command injection in ClearOS Webconfig's log viewer. The Python entry point, CVE-2026-67599.py, uses requests.Session to authenticate to the ClearOS Webconfig login endpoint on HTTPS port 81, captures the ci_csrf_token cookie, then submits a second POST to /app/log_viewer/index with file=system and a malicious filter parameter containing shell command substitution syntax $(...). The operator can supply arbitrary commands with -c; the default command writes an artifact to /tmp/lazytitanwazhere. The exploit is operational rather than a mere detector because it performs the full login-and-trigger sequence and supports arbitrary command execution. The README expands on impact, identifies the vulnerable backend file (/usr/clearos/apps/base/libraries/File.php), and demonstrates post-exploitation including a reverse shell and privilege escalation from the webconfig account to root using permissive default sudoers rules, notably via sudo tar. Overall, the repository's purpose is to provide a working authenticated RCE PoC and supporting vulnerability write-up for ClearOS 7.9.1.342252.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.