Skip to content
feed: live
0dayNews
CVE Record
[ HIGH ]CVE-2026-105133

OS command injection in AhsayCBS backup management console

AhsayCBS OS command injection via manipulated function arguments allows SYSTEM-level code execution. Chained with CVE-2026-105134 for unauthenticated RCE. No patch available.

Vendor
Ahsay Systems
Product
AhsayCBS
CVSS
7.3
EPSS (exploit probability)
0.4%
Status
exploited-in-wild
Published

CVE-2026-105133 is a CVSS 7.3 OS command injection flaw in AhsayCBS, the backup management platform from Ahsay Systems. An attacker with access to the management console can manipulate arguments passed to certain functions, executing arbitrary OS commands with SYSTEM-level privileges.

Huntress disclosed the vulnerability on October 4, 2026. Versions up to and including 10.3.4 are affected.

When combined with the authentication bypass CVE-2026-105134 (CVSS 10.0), CVE-2026-105133 becomes part of an unauthenticated remote code execution chain requiring no valid credentials.

Exploitation status: Active exploitation confirmed as of October 7, 2026. The command injection capability has been used to install JSP webshells and XMRig cryptocurrency miners on compromised hosts.

Mitigation: No patch is available. Block all external access to the AhsayCBS management interface and investigate any systems running the software for indicators of compromise.