Description
A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component.
Published: 2026-10-04
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Improper authentication allowing unauthorized access
Action: Patch
AI Analysis

Impact

Ahsay AhsayCBS contains a flaw in the checkSysPwd function of the ApiStructsAction component that permits attackers to bypass authentication by manipulating the random argument. This vulnerability is a classic example of improper authentication (CWE-287) and could allow an attacker to gain unauthorized access to the system’s API endpoints, potentially exposing sensitive data or enabling further exploitation.

Affected Systems

The vulnerability affects Ahsay AhsayCBS versions up to 10.3.2. Ahsay released mitigation in version 10.3.4, which should be applied to eliminate the flaw.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the vulnerability is exploitable remotely. Although EPSS data is not available and the issue is not listed in CISA KEV, the public nature of the exploit and the ability to trigger it by manipulating an input argument make it a realistic threat. Proper authentication checks are not enforced when the random parameter is altered, allowing attackers to impersonate legitimate users without needing valid credentials.

Generated by OpenCVE AI on October 4, 2026 at 07:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to AhsayCBS 10.3.4 or later to remove the vulnerable code.
  • If the update cannot be applied immediately, restrict access to the affected API endpoints using firewall rules or network segmentation, allowing only trusted IP ranges to interact with the service.
  • Enable detailed authentication logs and monitor for attempts that manipulate the random argument or show unauthorized access, reporting any suspicious behavior to the security team.

Generated by OpenCVE AI on October 4, 2026 at 07:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component.
Title Ahsay AhsayCBS API ApiStructsAction.java checkSysPwd improper authentication
First Time appeared Ahsay
Ahsay ahsaycbs
Weaknesses CWE-287
CPEs cpe:2.3:a:ahsay:ahsaycbs:*:*:*:*:*:*:*:*
Vendors & Products Ahsay
Ahsay ahsaycbs
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T05:15:14.561Z

Reserved: 2026-10-03T13:13:31.953Z

Link: CVE-2026-105133

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T07:16:33.087

Modified: 2026-10-04T07:16:33.087

Link: CVE-2026-105133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T08:00:15Z

Weaknesses