Description
A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve this issue. Upgrading the affected component is advised.
Published: 2026-10-04
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: Remote OS Command Execution
Action: Patch Now
AI Analysis

Impact

The vulnerability occurs in the Replication Receiver component of Ahsay CBS, where a malicious value supplied to the 'random' parameter of the /rps/api/json/UpdateReceivers.do endpoint can cause arbitrary OS commands to be executed. This flaw is a classic command injection (CWE‑77/CWE‑78). Successfully exploited, an attacker can gain full control of the server, exfiltrate data, or pivot to other systems, impacting confidentiality, integrity, and availability.

Affected Systems

Affected versions of Ahsay CBS are all releases up to 10.3.2. Versions 10.3.4 and later contain the fix. The software is deployed in enterprise environments managing data replication, and the vulnerability exists in the server‑side code handling replication receiver updates.

Risk and Exploitability

The CVSS score of 10 indicates critical severity. The exploit is publicly available and can be launched remotely via an HTTP request, and it has been reported as published. The EPSS score is not disclosed, but the lack of an available EPSS does not diminish the seriousness of the known exploit. The vulnerability is not listed in CISA’s KEV catalog, yet the documented public exploit and remote launch capability make it an immediate priority for patching.

Generated by OpenCVE AI on October 4, 2026 at 07:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Ahsay CBS installation to version 10.3.4 or later to apply the vendor patch that sanitizes the 'random' parameter and mitigates command injection.
  • If a rapid upgrade is not feasible, restrict network access to the /rps/api/json/UpdateReceivers.do URL to trusted hosts and employ web‑application firewall rules that block shell‑special characters from the 'random' parameter.
  • Enforce strict input validation on all received parameters and apply the principle of least privilege to the system account executing within the replication receiver process.

Generated by OpenCVE AI on October 4, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve this issue. Upgrading the affected component is advised.
Title Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection
First Time appeared Ahsay
Ahsay ahsaycbs
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:ahsay:ahsaycbs:*:*:*:*:*:*:*:*
Vendors & Products Ahsay
Ahsay ahsaycbs
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 10, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T05:30:12.882Z

Reserved: 2026-10-03T13:13:35.953Z

Link: CVE-2026-105134

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T07:16:33.480

Modified: 2026-10-04T07:16:33.480

Link: CVE-2026-105134

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T09:00:08Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')