CVE-2026-66147
Medium
Elevated severity or exploit probability.
CVSS base
9.4
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
EPSS — probability of exploitation (30 days)
1.8%
77.1th percentile
CISA KEV
Not listed
Weakness / dates
CWE-94
Published 2026-08-11 · modified 2026-08-28
Description
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.