A critical OS command injection flaw in the Replication Receiver component of Ahsay AhsayCBS through version 10.3.2 can be exploited remotely without authentication, and a public exploit has been released.
What Is It
CVE-2026-105134 affects the Replication Receiver component of Ahsay AhsayCBS. The bug is in the file /rps/api/json/UpdateReceivers.do. If an attacker manipulates the random argument, they can inject OS commands. The flaw is classified as CWE-77 (Command Injection) and CWE-78 (OS Command Injection).
VulDB, the CNA, reported the issue and NVD published it on October 4, 2026. NVD lists its status as "Received," which means NVD has not yet done its own analysis.
Why It Matters
The CVSS v3.1 base score is 10.0 (Critical), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. In plain terms:
- Network-reachable: it can be attacked remotely.
- Easy to exploit: low attack complexity, with no privileges and no user interaction needed.
- Broad impact: scope is changed, with high impact to confidentiality, integrity and availability.
The CVSS v4.0 score is 9.3 (Critical), with exploit maturity rated Proof-of-Concept. The advisory says the exploit "has been published and may be used."
At the time of writing, the CVE did not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. That means no CISA-mandated action or due date applies, and the available data does not confirm active exploitation. Even so, a public exploit for an unauthenticated, network-reachable command injection makes patching urgent.
What's Vulnerable
- Vendor: Ahsay
- Product: AhsayCBS
- Component: Replication Receiver
- Affected versions: up to and including 10.3.2 (10.3.0, 10.3.1 and 10.3.2 are listed as affected)
- Unaffected version: 10.3.4
- CPE:
cpe:2.3:a:ahsay:ahsaycbs:*:*:*:*:*:*:*:*
Patch Status
A fix is available. The advisory says upgrading to AhsayCBS 10.3.4 resolves the issue and recommends upgrading the affected component. Ahsay's 10.3.4 release notes are listed in the references.