High severity8.8NVD Advisory· Published Jan 26, 2026· Updated Jun 17, 2026
CVE-2026-1428
CVE-2026-1428
Description
Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:wellchoose:single_sign-on_portal_system:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:wellchoose:single_sign-on_portal_system:*:*:*:*:*:*:*:*range: <iftop_p4_181
- (no CPE)
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
2- www.twcert.org.tw/en/cp-139-10655-59160-2.htmlnvdThird Party Advisory
- www.twcert.org.tw/tw/cp-132-10654-23f40-1.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.