CVE-2026-26009

CRITICAL

Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server templates execute directly on the host operating s...

Affects 0 products across 4 vendors.

BCS7.14
CVSS 3.19.9
EPSS0.5%
Percentile39th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-78
CAPEC-108 Command Line Execution through SQL Injection
via CWE-78
CAPEC-6 Argument Injection
via CWE-78
CAPEC-15 Command Delimiters
via CWE-78
CAPEC-88 OS Command Injection
via CWE-78

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

CVE-2026-26009 affects Catalyst, an enterprise game server platform, by allowing users with template.create or template.update permissions to execute arbitrary shell commands as root, leading to full system compromise.

BSID: BS-2026-GLOBAL-074805-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-26009?
CVE-2026-26009 affects Catalyst, an enterprise game server platform, by allowing users with template.create or template.update permissions to execute arbitrary shell commands as root, leading to full system compromise.
What is the CVSS score for CVE-2026-26009?
CVE-2026-26009 has CVSS 9.9 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. EPSS: 0.5%.
Is CVE-2026-26009 actively exploited?
No confirmed active exploitation of CVE-2026-26009 as of 2026-05-30.
How do I remediate CVE-2026-26009?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-26009?
CVE-2026-26009 affects: Catalyst, Full, Platform, Scripts.
Vulnerability Details
CVE IDCVE-2026-26009
BSIDBS-2026-GLOBAL-074805-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Published2026-02-10
Last Modified2026-04-15
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server templates execute directly on the host operating system as root via bash -c, with no sandboxing or containerization. Any user with template.create or template.update permission can define arbitrary shell commands that achieve full root-level remote code execution on every node machine in the cluster. This vulnerability is fixed in commit 11980aaf3f46315b02777f325ba02c56b110165d.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises from the installation scripts in server templates executing directly on the host OS as root without any sandboxing or containerization. This allows an attacker with the necessary permissions to inject malicious commands.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Catalyst —
Full —
Platform —
Scripts —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 178 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash15d7a2f40809d949ce6c020847de2bca0e458cb0ee7ceb3ad78be3c9d537df19caae50a762c87c316b77f168d9a891849c8ebda90d6bf7fee27fab47efceeb83
Related CVEs affecting Catalyst
CVE-2025-20341 8.8 A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an aut... CVE-2026-20086 8.6 A vulnerability in the processing of Control and Provisioning of Wireless Acc... CVE-2026-20224 8.6 A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-W... CVE-2026-20084 8.6 A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could a... CVE-2025-40920 8.6 Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Per...
View all Catalyst CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.9 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →