CVE-2026-66145
Description
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.
In plain language
AI Act nowGMS (up to 9.5.1, Build 9510.1044) has a security hole that lets an attacker over the network run harmful commands on the server without needing an account; typical small businesses should treat this as serious and act now.
Unauthenticated remote code execution exists in gms (GMS 9.5.1 Build 9510.1044 and earlier), enabling network attackers without credentials to execute unauthorized code and access sensitive data.
What to do now
- Check whether you run gms and confirm the installed version/build (it is affected if you are on GMS 9.5.1 (Build 9510.1044) or earlier).
- Verify whether the vulnerable gms service is reachable from the internet (default config is reachable).
- If it is internet-reachable, block access at your firewall/VPN so only trusted admin networks can reach it.
- Look for an official update/patch from your software vendor for gms; if none is available yet, plan an urgent upgrade path or compensating controls with your IT/vendor.
- Monitor for suspicious inbound requests targeting gms and review logs for unusual command/file activity.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-66145 and every CVE in our database. Create a free account — no credit card required.
Create Free Account