Cyber & AI intelligence
Wasteland.
Briefs indexed3004
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-105134 2026-10-04

Ahsay AhsayCBS Replication Receiver Flaw Allows Unauthenticated Remote OS Command Injection (CVE-2026-105134)

"A critical OS command injection flaw in the Replication Receiver component of Ahsay AhsayCBS through version 10.3.2 can be exploited remotely without authentication, and a public exploit has been released."

A critical OS command injection flaw in the Replication Receiver component of Ahsay AhsayCBS through version 10.3.2 can be exploited remotely without authentication, and a public exploit has been released.

What Is It

CVE-2026-105134 affects the Replication Receiver component of Ahsay AhsayCBS. The bug is in the file /rps/api/json/UpdateReceivers.do. If an attacker manipulates the random argument, they can inject OS commands. The flaw is classified as CWE-77 (Command Injection) and CWE-78 (OS Command Injection).

VulDB, the CNA, reported the issue and NVD published it on October 4, 2026. NVD lists its status as "Received," which means NVD has not yet done its own analysis.

Why It Matters

The CVSS v3.1 base score is 10.0 (Critical), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. In plain terms:

The CVSS v4.0 score is 9.3 (Critical), with exploit maturity rated Proof-of-Concept. The advisory says the exploit "has been published and may be used."

At the time of writing, the CVE did not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. That means no CISA-mandated action or due date applies, and the available data does not confirm active exploitation. Even so, a public exploit for an unauthenticated, network-reachable command injection makes patching urgent.

What's Vulnerable

Patch Status

A fix is available. The advisory says upgrading to AhsayCBS 10.3.4 resolves the issue and recommends upgrading the affected component. Ahsay's 10.3.4 release notes are listed in the references.

Sources