Skip to content
Threat Feed
critical advisory PoC updated

Unauthenticated Remote Code Execution in Ahsay AhsayCBS

Ahsay AhsayCBS up to version 10.3.2 is vulnerable to unauthenticated remote OS command injection via the /rps/api/json/UpdateReceivers.do endpoint, enabling full system compromise.

CVE search metadata

CVE search record: CVE-2026-105134. Severity: critical. CVSS: 10.0. EPSS: 1.84%. KEV: no. Product: AhsayCBS (< 10.3.4), AhsayCBS (<= 10.3.2), AhsayCBS (<= 10.3.4). Brief: Unauthenticated Remote Code Execution in Ahsay AhsayCBS. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ahsay-cbs-rce/

CVE search record: CVE-2026-105133. Severity: high. CVSS: 7.3. EPSS: 0.38%. KEV: no. Product: AhsayCBS (< 10.3.4), AhsayCBS (<= 10.3.2), AhsayCBS (<= 10.3.4). Brief: Unauthenticated Remote Code Execution in Ahsay AhsayCBS. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ahsay-cbs-rce/

What's new

  • 1. OS windows Oct 9, 10:40 via securityweek
  • 2. poc_available; added CVE-2026-105133 Oct 5, 15:44 via sploitus
  • 3. added coverage for AhsayCBS (<= 10.3.2) Oct 4, 09:01 via nvd

Ahsay AhsayCBS, a backup software solution, contains a critical security vulnerability (CVE-2026-105134) in the Replication Receiver component. The flaw exists within the /rps/api/json/UpdateReceivers.do endpoint, where the 'random' argument is processed in an insecure manner. An unauthenticated remote attacker can inject arbitrary OS commands by manipulating this argument, leading to complete unauthorized access and execution of code with the privileges of the AhsayCBS application. With a CVSS base score of 10.0, this vulnerability poses a severe risk to organizations using the affected software. Publicly available exploit code has been reported, significantly increasing the likelihood of exploitation. Administrators must upgrade to version 10.3.4 immediately to remediate the vulnerability.

Impact

Successful exploitation of this vulnerability allows an unauthenticated remote attacker to execute arbitrary system commands, leading to full server compromise, data exfiltration, or deployment of additional malicious payloads such as ransomware. The impact is critical, affecting any environment where AhsayCBS is exposed to the network.

Recommendation

  • Upgrade all instances of AhsayCBS to version 10.3.4 or later immediately.
  • Apply the rules below to identify exploitation attempts targeting the identified API endpoint.
  • Restrict network access to the AhsayCBS management interface to trusted IP addresses only, especially for the Replication Receiver component.

Immediate actions

Upgrade AhsayCBS to 10.3.4

IT Operations 24h

Mitigations

Patch AhsayCBS to 10.3.4

immediate IT Operations

CVE-2026-105134

Detection coverage 1

Detects CVE-2026-105134 Exploitation - Unauthenticated RCE via /rps/api/json/UpdateReceivers.do

critical

Detects exploitation attempts against CVE-2026-105134 by identifying suspicious command injection patterns in the 'random' parameter of the UpdateReceivers.do endpoint.

sigma tactics: execution, initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →