Unauthenticated OS Command Injection in Openfind SecuShare Pro
Openfind SecuShare Pro is vulnerable to an unauthenticated OS command injection flaw (CVE-2026-107459) allowing remote attackers to execute arbitrary commands on the host server.
CVE search metadata
CVE search record: CVE-2026-107459. Severity: critical. CVSS: 9.8. KEV: no. Product: SecuShare Pro. Brief: Unauthenticated OS Command Injection in Openfind SecuShare Pro. Brief link: https://feed.craftedsignal.io/briefs/2026-10-secushare-rce/
Openfind SecuShare Pro contains a critical OS command injection vulnerability, identified as CVE-2026-107459. This vulnerability permits unauthenticated remote attackers to send specially crafted requests to the application, resulting in the execution of arbitrary operating system commands with the privileges of the web service. With a CVSS v3.1 base score of 9.8, this flaw represents a significant risk to organizations using the SecuShare Pro solution, as it enables full system compromise without requiring prior authentication or user interaction. Defenders should prioritize identifying instances of this software within their network and monitoring for abnormal process execution originating from the web server process.
Impact
Successful exploitation leads to full remote code execution on the underlying server hosting SecuShare Pro. This can result in complete system compromise, unauthorized data exfiltration, lateral movement within the network, and the deployment of additional malware or ransomware.
Recommendation
Prioritize the identification of all internet-facing or internal SecuShare Pro instances. Monitor web server logs for suspicious parameter values containing common command injection indicators (e.g., semicolon, pipe, or backtick characters) directed at the application API. Check for unexpected child processes being spawned by the web service process (e.g., cmd.exe, sh, bash) and investigate any suspicious outbound network activity originating from the application server.
Immediate actions
Patch or upgrade affected SecuShare Pro deployments to a version that addresses CVE-2026-107459.
Threat Hunt
Web server access logs for unusual command injection patterns in POST/GET requests
Data: webserver logs
Mitigations
Restrict external access to the SecuShare Pro management interface
CVE-2026-107459