Improper authentication in Gaia - CVE-2026-18574
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to improper authentication in management authentication on the Security Management Server when handling management access requests. A remote attacker can bypass authentication to execute arbitrary commands.
Successful exploitation requires network access to the Security Management Server. Environments that do not restrict Trusted Clients or that expose Management services to untrusted networks may have increased exposure.