Description
Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/run_test/ endpoint to execute arbitrary commands as the Spug process user.
Published: 2026-09-13
Score: 8.7 High
EPSS: 1.3% Low
KEV: No
Impact: Remote Code Execution
Action: Apply Update
AI Analysis

Impact

Spug failing to sanitize user-supplied monitor addresses causes the ping_check function to interpolate those strings directly into shell commands. An attacker who to the /monitor/run_test/ endpoint, inject shell metacharacters, and trigger arbitrary commands to execute in the context of the Spug process user. This grants the attacker remote code execution on the host, potentially enabling full system compromise. This vulnerability represents a CWE-78 OS Command Injection flaw.

Affected Systems

The vulnerability exists in the openspug:spug product through version 3.4.0. Any deployment that has not upgraded beyond v3.4.0 is susceptible.

Risk and Exploitability

The CVSS score of 8.7 makes this a high‑1% indicates a low but nonzero exploitation probability. The minimal prerequisites—only authentication with monitor permissions—suggest a significant likelihood of successful exploitation. The vulnerability is not listed in CISA KEV, but that status does not reduce the threat level; remote command execution remains possible. Successful exploitation would enable total compromise of the host system.

Generated by OpenCVE AI on September 15, 2026 at 16:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Add input validation to the /monitor/run_test endpoint to escape or reject shell metacharacters in monitor addresses, following CWE-78 mitigation guidelines.
  • Restrict access to the /monitor/run_test endpoint so that only trusted users with monitor permission can use it.
  • Disable or remove the /monitor/run_test endpoint if monitoring is not required.
  • Monitor web logs for unexpected requests to /monitor/run_test and investigate suspicious activity promptly.

Generated by OpenCVE AI on September 15, 2026 at 16:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Openspug
Openspug spug
Vendors & Products Openspug
Openspug spug

Sun, 13 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/run_test/ endpoint to execute arbitrary commands as the Spug process user.
Title Spug through 3.4.0 Remote Code Execution via ping_check
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:51.257Z

Reserved: 2026-09-13T10:14:52.802Z

Link: CVE-2026-90770

cve-icon Vulnrichment

Updated: 2026-09-18T17:17:08.300Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T11:17:01.453

Modified: 2026-09-23T17:17:44.337

Link: CVE-2026-90770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')