CVE-2026-107459 is a critical OS command injection flaw in Openfind's SecuShare Pro. Unauthenticated remote attackers can use it to run arbitrary operating system commands on the server.
What Is It
CVE-2026-107459 is an OS Command Injection vulnerability (CWE-78) in SecuShare Pro, developed by Openfind. The NVD record says unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
TWCERT/CC ([email protected]) reported the flaw. NVD published the record on 2026-10-08, and its status is "Received." NVD has not yet completed its own analysis.
Why It Matters
The flaw carries a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The CVSS v4.0 score is 9.3 (CRITICAL).
The scoring describes the worst-case profile for a server-side bug:
- Attack vector: network
- Attack complexity: low
- Privileges required: none
- User interaction: none
- Impact: high to confidentiality, integrity and availability
Any attacker who can reach a vulnerable SecuShare Pro instance over the network could potentially take full control of the server's command execution context, without credentials or any action by a user.
Exploitation status: The supplied CISA KEV data contains no entry for this CVE, so CISA has not confirmed active exploitation in the source material. The CVSS v4.0 Exploit Maturity metric is also "Not Defined." Lack of KEV listing does not mean the flaw is not being exploited, and the severity profile justifies treating it as a priority.
What's Vulnerable
| Vendor | Product | Affected Version |
|---|---|---|
| Openfind | SecuShare Pro | 4 |
The record's default status for other versions is "unaffected." NVD has not yet published any CPE configurations.
Patch Status
The supplied NVD record includes no patched version numbers or vendor remediation steps. Because there is no KEV entry, there is also no CISA required action or due date.
Organizations running SecuShare Pro version 4 should:
- Check the TWCERT/CC advisories listed below for vendor fix and upgrade guidance.
- Apply Openfind's update as soon as it is available.
- Until it is patched, limit network exposure of SecuShare Pro instances, especially from the internet, given the unauthenticated network attack vector.