External risk intelligence

GMS Dispatcher Service Command Injection Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-66147

The GMS Dispatcher Service functions as a management and communication component within enterprise software. Such services are commonly deployed in configurations that allow for remote network access to facilitate management tasks or system orchestration, making them plausible targets for internet-facing exposure in standard deployments.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An unauthenticated command injection vulnerability has been identified in the GMS Dispatcher Service. This issue could allow remote attackers to execute code on affected systems through specially crafted requests, potentially impacting systems running GMS 9.5.1 and earlier.

  • Attackers can inject commands remotely.
  • This could allow unauthorized code execution.
  • Confirm relevance and assess exposure to GMS.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can reach the GMS Dispatcher Service over the network and send specially crafted requests. This could allow them to execute arbitrary commands on the affected system.

  • No authentication required.
  • Specially crafted network requests.
  • Remote code execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an unauthenticated remote attacker could execute arbitrary code on the system. This could potentially allow an attacker to take control of the affected service, impacting its confidentiality, integrity, and availability.

  • System asset at risk.
  • Arbitrary code execution.
  • Complete system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The GMS Dispatcher Service, identified in GMS 9.5.1 and earlier, presents a critical unauthenticated command injection risk. This vulnerability necessitates immediate action from teams responsible for application security and infrastructure management. The first practical step involves identifying all instances of the affected GMS versions, assessing their network exposure and business criticality, and locating the accountable owner for remediation planning.

  • Application and infrastructure owners should lead.
  • Verify GMS instances and network exposure.
  • Plan risk-based remediation or vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the GMS Dispatcher Service?

The GMS Dispatcher Service is a core management and communication component within the GMS platform. It is typically used in enterprise environments to handle system orchestration, data flow, and administrative tasks across the software's infrastructure.

What does command injection mean for CVE-2026-66147?

This vulnerability is classified as CWE-94, or Improper Control of Generation of Code. In the context of CVE-2026-66147, it means the service fails to properly sanitize inputs, allowing an attacker to insert their own commands into the system's processing logic, which the server then executes as if they were legitimate instructions.

How does an attacker trigger this GMS vulnerability?

An attacker triggers the vulnerability by sending a specially crafted request over the network to the GMS Dispatcher Service. Because the service does not require authentication to process these requests, the bug is not triggered by standard, authorized user interactions, but rather by malicious payloads specifically designed to exploit the injection flaw.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal indicates that because the GMS Dispatcher Service facilitates remote management and orchestration, it is often placed in network configurations that are reachable from outside the internal network. Systems that are internet-facing are at a much higher risk of exploitation compared to those isolated within a restricted, internal-only segment.

What should I do if I run GMS 9.5.1 or earlier?

Your first step is to locate all active instances of GMS within your environment to determine which ones are running version 9.5.1 or earlier. Once identified, evaluate their network exposure to see if they are reachable from the internet and coordinate with the system owners to prioritize these assets for remediation according to your internal security policies.

References