CVE-2026-3064 | HummerRisk up to 1.5.0 Cloud Task Scheduler ResourceCreateService.java regionId command injection
A vulnerability was found in HummerRisk up to 1.5.0 and classified as critical. Affected by this issue is some unknown functionality of the file ResourceCreateService.java of the component Cloud Task Scheduler. Such manipulation of the argument regionId leads to command injection.
This vulnerability is traded as CVE-2026-3064. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.