Command injection in Digital Employee Experience (DEX) - CVE-2026-2695
Published: May 19, 2026
Digital Employee Experience (DEX)
Detailed vulnerability description
The vulnerability allows a remote user to execute elevated commands on devices connected to the platform.
The vulnerability exists due to improper input validation in specific instructions when processing instruction input. A remote user can inject commands in specific instructions to execute elevated commands on devices connected to the platform.
Exploitation requires at least questioner privileges.