All CVEs
Vulnerability intelligence

CVE-2026-29202

CWE-94

Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.

CVSS Score
8.8
High
EPSS — Exploit Probability
0.8%
Riskier than 54% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
NVD entry Vendor patch PoC / advisory

2 articles across 2 outlets · first covered May 9, 2026 · latest May 10, 2026

Coverage timeline