A vulnerability described as critical has been identified in CoolerControl coolercontrold up to 3.x. This issue affects some unknown processing of the component Alerts. Such manipulation leads to os command injection.

This vulnerability is listed as CVE-2026-5208. The attack must be carried out locally. There is no available exploit.

Upgrading the affected component is recommended.