Apache Continuum Command Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A command injection vulnerability allowing remote code execution has been identified in Apache Continuum. This issue affects all versions of the software. The vulnerability arises from improper neutralization of special elements used in commands, which can be exploited by attackers with access to the installation's REST API to invoke arbitrary commands on the server. As Apache Continuum is a retired project, no official fix will be released. Users are advised to seek alternatives or restrict access to trusted users.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the server where Apache Continuum is installed.

Added: Jan 26, 2026, 12:18 PM
Updated: Jan 26, 2026, 7:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
10.0
exploitability
6.3
remediation
8.3
relevance
2.4
threat
0.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.