Ahsay · Ahsaycbs · CVE-2026-105134
**Name of the Vulnerable Software and Affected Versions**
Ahsay AhsayCBS versions prior to 10.3.4
**Description**
An OS command injection flaw exists in the Replication Receiver component. A remote attacker can exploit this by manipulating the `random` argument within the '/rps/api/json/UpdateReceivers.do' endpoint, allowing for the execution of arbitrary operating system commands.
**Recommendations**
Upgrade to version 10.3.4.