{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/spug/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:spug:spug:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-90770"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Spug (\u003c= 3.4.0)"],"_cs_severities":["high"],"_cs_tags":["webserver","rce","command-injection"],"_cs_type":"advisory","_cs_vendors":["Spug"],"content_html":"\u003cp\u003eSpug, an open-source server management platform, contains a critical remote code execution vulnerability (CVE-2026-90770) in the ping_check function. The application fails to properly sanitize user-supplied monitor addresses before passing them into shell commands. This vulnerability allows an authenticated attacker possessing monitor-level permissions to trigger command injection by supplying shell metacharacters through the /monitor/run_test/ endpoint. Successful exploitation results in arbitrary code execution with the privileges of the Spug process user. Given the administrative nature of the application, this vulnerability poses a significant risk for lateral movement and full system compromise within the server environments where Spug is deployed.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-90770 allows an authenticated attacker to execute arbitrary commands on the underlying host. This can lead to unauthorized access to server configurations, credential theft, and full system takeover. Organizations utilizing Spug for server management are at high risk if they have allowed untrusted or compromised accounts to hold monitor-level permissions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate upgrade of all Spug instances to a version released after 3.4.0 that addresses CVE-2026-90770. Monitor web server logs for suspicious requests to the /monitor/run_test/ endpoint that contain shell metacharacters such as semicolons, pipes, or command substitution sequences. Restrict access to the monitoring and administrative modules of the Spug application to trusted personnel only until the software is updated.\u003c/p\u003e\n","date_modified":"2026-09-13T11:26:00Z","date_published":"2026-09-13T11:26:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-spug-rce/","summary":"Spug versions 3.4.0 and earlier are vulnerable to authenticated remote code execution due to improper shell command validation in the ping_check function.","title":"Remote Code Execution in Spug via Command Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-spug-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Spug","version":"https://jsonfeed.org/version/1.1"}