CVE-2026-66147
critical · 9.4An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.
9.4
CVSS
1.8%
EPSS (exploit prob.)
77th
EPSS percentile
2026-08-11
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Weaknesses
CWE-94
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-66147