Security Advisory

CVE-2026-7246

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-30 13:16:44
Last updated 2026-08-18 20:50:52
Assigner certcc
CVSS score 7.2
State PUBLISHED

Description

This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below: Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.