Security Advisory

CVE-2026-7246

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-30 13:16:44
Last updated 2026-07-15 00:40:20
Assigner certcc
CVSS score not scored
State PUBLISHED

Description

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.