Security advisory: Authenticated RCE (command injection) in Kerio Connect 10.0.9 Patch 2 (build 10320) (GFI Software)
Full Disclosuremailing list archivesFrom: disclosure via Fulldisclosure <fulldis 2026-8-18 06:17:44 Author: seclists.org(查看原文) 阅读量:3 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: disclosure via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 18 Aug 2026 06:04:56 +0000

0day Rubbish Research Team is publicly disclosing a vulnerability in Kerio Connect 10.0.9 Patch 2 (build 10320) (GFI 
Software). The research is published and a proof-of-concept is available.

Authenticated RCE (command injection) (CVSS 8.8, authenticated)

Kerio Connect 10.0.9 Patch 2 contains a command-injection vulnerability in the WebAdmin JSON-RPC method 
Server.startEncryption. The password parameter is double-quoted and concatenated unescaped into a cryptsetup shell 
command that is executed via system() during volume encryption. Because the mail server process runs as root, a 
FullAdmin user can break out of the quotes and execute arbitrary commands as root. Dynamically verified.

Impact: Arbitrary command execution as root on the mail server host. An attacker with admin access can read mail stores 
and credentials, disrupt mail service, and take full control of the server.

Advisory: https://0day-rubbish.com/blog/kerio-connect-startencryption-cmd-injection-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

Vendor has been notified. CVE ID is pending.

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/


Current thread:

  • Security advisory: Authenticated RCE (command injection) in Kerio Connect 10.0.9 Patch 2 (build 10320) (GFI Software) disclosure via Fulldisclosure (Aug 17)

文章来源: https://seclists.org/fulldisclosure/2026/Aug/62
如有侵权请联系:admin#unsafe.sh