CVE•Published 2026-07-28•Modified 2026-07-28•0 articles on news•4 live references•NVD data
CVE-2026-16313
Vulnerability data via NVD (ingested)
CVSS v3.1
7.6
HIGH
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS percentile
—
Description
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
Timeline
Published 2026-07-28
Modified 2026-07-28
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
More intel sources (5)
Shodan report
vuln:CVE-2026-16313Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-16313Censys host search filtered to this CVE id.
grep.app
CVE-2026-16313Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-16313GitHub code search for direct mentions.
Google dork
"CVE-2026-16313" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (2)
CVE-2026-163132 repos
Mr-xn/Penetration_Testing_POCHTML
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypas…
Threekiii/Awesome-POCJava
一个漏洞 PoC 知识库。A knowledge base for vulnerability PoCs(Proof of Concept), with 1k+ vulnerabilities.
We haven't classified any articles referencing CVE-2026-16313 yet. The external references above still apply.