high
advisory
Authentication Bypass in OSSRS srs System API
OSSRS srs versions 7.0-a1 and earlier are vulnerable to an unauthenticated remote execution flaw in the System API component due to missing authentication controls in the systemAPI.Run function.
CVE search metadata
CVE search record: CVE-2026-105486. Severity: high. CVSS: 7.3. KEV: no. Brief: Authentication Bypass in OSSRS srs System API. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ossrs-srs-auth-bypass/
A security vulnerability (CVE-2026-105486) has been identified in OSSRS s