A vulnerability was found in NSA Emissary up to 8.38.x. It has been classified as critical. Affected by this issue is the function Executrix of the component Configuration Handler. The manipulation of the argument PLACE_NAME leads to os command injection.

This vulnerability is traded as CVE-2026-35581. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is recommended.