Home

Description

OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.21.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS.

PUBLISHED Reserved 2026-05-08 | Published 2026-05-08 | Updated 2026-05-08 | Assigner TRO




CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')

Product status

Default status
unaffected

Any version before 5.25.1
affected

Credits

Vera Mens of Claroty Team82 finder

References

www.universal-robots.com/...ation-protocol/dashboard-server/

cve.org (CVE-2026-8153)

nvd.nist.gov (CVE-2026-8153)

Download JSON