Authentication bypass in AhsayCBS backup management console
Unauthenticated attackers can substitute a random token for valid credentials in AhsayCBS, gaining full console access. Actively exploited with no patch available as of October 2026.
- Vendor
- Ahsay Systems
- Product
- AhsayCBS
- CVSS
- 10.0
- EPSS (exploit probability)
- 1.8%
- Status
- exploited-in-wild
- Published
CVE-2026-105134 is a CVSS 10.0 authentication bypass in AhsayCBS, the backup management platform from Ahsay Systems. The flaw allows an unauthenticated remote attacker to substitute a randomly generated token in place of valid credentials, bypassing the login requirement entirely.
Huntress researchers disclosed the vulnerability on October 4, 2026, noting that public exploit code was already available at the time of disclosure. Versions up to and including 10.3.4 (the current release) are confirmed vulnerable.
When chained with CVE-2026-105133, which is an OS command injection flaw in the same product, CVE-2026-105134 enables unauthenticated remote code execution with SYSTEM privileges.
Exploitation status: Active exploitation confirmed by Huntress against at least five organizations as of October 7, 2026. Attackers have deployed JSP webshells and XMRig cryptocurrency miners disguised as MicrosoftEdgeUpdateSvc.
Mitigation: No patch is available. Restrict the AhsayCBS management interface to trusted IP addresses only until Ahsay Systems issues a fix.
