PT-2026-104599 · Ahsay · Ahsaycbs

·

CVE-2026-105134

·

Published

2026-10-03

·

Updated

2026-10-04

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ahsay AhsayCBS versions prior to 10.3.4
Description An OS command injection flaw exists in the Replication Receiver component. A remote attacker can exploit this by manipulating the random argument within the '/rps/api/json/UpdateReceivers.do' endpoint, allowing for the execution of arbitrary operating system commands.
Recommendations Upgrade to version 10.3.4.

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105134

Affected Products

Ahsaycbs