{"id":"CVE-2026-50772","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-50772","summary":"An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function.","details":"An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function.","published":"2026-08-17T18:17:09.207","modified":"2026-08-18T19:16:54.473","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://docs.squirro.com/en/latest/products/cognitive-search.html"},{"type":"WEB","url":"https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2026-50772"},{"type":"WEB","url":"https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2026-50772"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T19:16:54.473"}}