ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to establish reverse shells and gain complete system control.
Metrics
Affected Vendors & Products
References
History
Sun, 17 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Acl
Acl acl Analytics |
|
| Vendors & Products |
Acl
Acl acl Analytics |
Sun, 17 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to establish reverse shells and gain complete system control. | |
| Title | ACL Analytics 11.x - 13.0.0.579 Arbitrary Code Execution | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-05-17T12:11:27.402Z
Updated: 2026-05-17T12:11:27.402Z
Reserved: 2026-05-17T11:34:33.230Z
Link: CVE-2018-25320
No data.
Status : Received
Published: 2026-05-17T13:16:43.270
Modified: 2026-05-17T13:16:43.270
Link: CVE-2018-25320
No data.