A AegiFlow
CRITICALCVSS 9.8EPSS 0.5%

CVE-2026-39006

SNMP4J-Agent allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component

Published
2026-06-15
Modified
2026-08-26
EPSS percentile
42%
Aliases
GHSA-7h7j-7vwp-cwfg
Sources
github-advisory

Summary

An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.snmp4j:snmp4j-agent

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.