{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aspotwebspotweb/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:spotweb:spotweb:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-108546"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Spotweb (\u003c= 1.5.8)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","remote-code-execution","command-injection"],"_cs_type":"threat","_cs_vendors":["Spotweb"],"content_html":"\u003cp\u003eSpotweb versions 1.5.8 and earlier contain a critical OS command injection vulnerability located within the application's NZB handler. The vulnerability stems from the unsafe handling of user-supplied spot titles retrieved from Usenet. An attacker can create a spot with a title containing shell metacharacters and publish it to the Usenet network. When a target user processes or downloads this specific spot, the Spotweb application substitutes the malicious title into the $SPOTTITLE variable, which is then passed directly to the PHP exec() function without proper sanitization. This results in the execution of arbitrary commands on the underlying host with the privileges of the web server process. This vulnerability is significant for defenders as it allows for unauthenticated remote code execution triggered by standard user interaction with the application interface.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for remote code execution, which can lead to full system compromise, data theft, and persistence within the victim's environment. The scope of impact is limited to organizations and individuals running self-hosted Spotweb instances up to version 1.5.8. Because the exploit relies on the processing of Usenet content, any internet-facing Spotweb installation is at risk if configured to sync with public Usenet indices.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and mitigation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade Spotweb instances to a version beyond 1.5.8 or apply the vendor-supplied security patch to remediate CVE-2026-108546.\u003c/li\u003e\n\u003cli\u003eAudit PHP execution logs to monitor for unexpected calls originating from the NZB handler component or unusual child processes spawned by the web server service.\u003c/li\u003e\n\u003cli\u003eImplement strict egress filtering on the host machine to prevent the web server process from initiating outbound connections to unauthorized external IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T15:55:12Z","date_published":"2026-10-10T15:55:12Z","id":"https://feed.craftedsignal.io/briefs/2026-10-spotweb-command-injection/","summary":"Spotweb versions 1.5.8 and earlier are vulnerable to remote code execution through the NZB handler, triggered by maliciously crafted Usenet spot titles.","title":"Remote Code Execution via OS Command Injection in Spotweb","url":"https://feed.craftedsignal.io/briefs/2026-10-spotweb-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:spotweb:spotweb:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}