Skip to content
Threat Feed
high advisory

Authentication Bypass in OSSRS srs System API

OSSRS srs versions 7.0-a1 and earlier are vulnerable to an unauthenticated remote execution flaw in the System API component due to missing authentication controls in the systemAPI.Run function.

CVE search metadata

CVE search record: CVE-2026-105486. Severity: high. CVSS: 7.3. KEV: no. Brief: Authentication Bypass in OSSRS srs System API. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ossrs-srs-auth-bypass/

A security vulnerability (CVE-2026-105486) has been identified in OSSRS s