CVE-2026-22781 - TinyWeb CGI Command Injection

CVE-2026-22781 - TinyWeb CGI Command Injection

CVE ID : CVE-2026-22781 Published : Jan. 12, 2026, 7:16 p.m. | 1 hour, 30 minutes ago Description : TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via CGI ISINDEX-style query parameters. The query parameters are passed as command-line arguments to the CGI executable via Windows CreateProcess(). An unauthenticated remote attacker can execute arbitrary commands on the server by injecting Windows shell metacharacters into HTTP requests. This vulnerability is fixed in 1.98. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
CRITICAL
Published
Jan. 12, 2026
Affected Product: Windows
Impact: command injection

Source: Telegram CVE Monitor