CVE-2026-1412 | Sangfor Operation and Maintenance Security Management System HTTP POST Request /fort/audit/get_clip_img command injection (CNNVD-202601-4425)
A vulnerability labeled as critical has been found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. The impacted element is an unknown function of the file /fort/audit/get_clip_img of the component HTTP POST Request Handler. Such manipulation of the argument frame/dirno leads to command injection.
This vulnerability is referenced as CVE-2026-1412. It is possible to launch the attack remotely. Furthermore, an exploit is available.