A vulnerability classified as critical was found in CubeCart up to 6.5.x. Impacted is an unknown function. Such manipulation leads to os command injection.

This vulnerability is uniquely identified as CVE-2026-21719. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.