CVE-2026-3120
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection. This issue affects SambaBox: from 5.1 before 5.3.
View on NVDAnalysis
SambaBox is an enterprise identity management appliance from a Turkish vendor with limited global or local presence in the Mexican development ecosystem. While the vulnerability allows OS command injection, its narrow deployment base makes it low priority for a general software development community feed.
Severity
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HCWE-94EPSS
Technical description
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection. This issue affects SambaBox: from 5.1 before 5.3.