SECURITYCRITICALCVE-2026-105134

CVE-2026-105134: AhsayCBS Replication Receiver OS Command Injection

A maximum-severity command injection flaw in AhsayCBS's Replication Receiver API lets attackers run arbitrary OS commands remotely.

Dylan H.

Security Team

October 4, 2026
6 min read
CVE-2026-105134: AhsayCBS Replication Receiver OS Command Injection

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Ahsay AhsayCBS — versions 10.3.0 through 10.3.2

Overview

A maximum-severity, CVSS 10.0 OS command injection vulnerability has been disclosed in AhsayCBS, the centralized backup server platform from Ahsay used by managed service providers to run cloud and local backup services for their clients. Tracked as CVE-2026-105134 and classified under CWE-77 (Command Injection) and CWE-78 (OS Command Injection), the flaw sits in the product's Replication Receiver component and lets a remote attacker execute arbitrary operating-system commands on the backup server without any authentication.

The vulnerable endpoint is POST /rps/api/json/UpdateReceivers.do, which feeds the random request argument into the checkSysPwd function of com/ahsay/obs/api/ApiStructsAction.java. Because that value is passed through to a system-level command without adequate sanitization, an attacker who can reach the endpoint over the network can inject shell metacharacters and run commands with the privileges of the AhsayCBS process — on a server whose entire purpose is holding backup copies of other organizations' data.

The issue was reserved on October 3, 2026 and published on October 4, 2026. Reporting on the flaw notes conflicting signals on public exploit availability: some vulnerability-intelligence feeds list a disclosed proof-of-concept, while others report no confirmed public exploit code as of publication. The CVE is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.


Technical Details

FieldValue
CVE IDCVE-2026-105134
CWECWE-77 (Command Injection), CWE-78 (OS Command Injection)
SeverityCritical
CVSS 3.1 Score10.0
CVSS 3.1 VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 4.0 Score9.3 (per vendor-independent scoring)
Attack VectorNetwork (Replication Receiver API)
AuthenticationNone required
Privileges RequiredNone
User InteractionNone
Affected SoftwareAhsay AhsayCBS 10.3.0, 10.3.1, 10.3.2
Fixed VersionAhsayCBS 10.3.4

How It Works

AhsayCBS exposes a Replication Receiver API used to synchronize backup data between AhsayCBS servers. The UpdateReceivers.do endpoint accepts a random parameter that is handled by the checkSysPwd function inside ApiStructsAction.java. That function builds a system-level call using the supplied value without sufficiently filtering shell metacharacters.

An attacker who can reach the endpoint — which, per the scoring vector's unauthenticated, network-exploitable profile, does not require a valid session — can craft a random value containing injected OS commands. The backend executes that value as part of a command-line operation, running the attacker's payload with the privileges of the AhsayCBS process. On a typical deployment, that process runs with enough access to read backup archives, configuration files containing storage and client credentials, and in many setups, enough system privilege to pivot further into the host.

Why This Is Different From a Typical Web App RCE

AhsayCBS is backup infrastructure — the whole point of the product is to be trusted with every client's data. An unauthenticated command-injection bug in that tier doesn't just compromise one application; it compromises the recovery point for everything the server backs up, and for managed service providers running AhsayCBS for multiple downstream customers, a single compromised server can expose many organizations' backup archives at once.


Impact Assessment

Impact AreaDescription
Remote Code ExecutionUnauthenticated attacker can execute arbitrary OS commands with AhsayCBS process privileges
Backup Data ExposureAccess to the backup server can expose archived data for every client/tenant the instance serves
Credential ExposureConfiguration files on the backup server commonly hold storage, replication, and client credentials reachable post-compromise
Supply Chain Risk for MSPsManaged service providers running AhsayCBS centrally put every downstream client at risk from a single compromised instance
Low Bar to ExploitNo authentication, no privileges, and no user interaction are required — network reachability to the endpoint is sufficient
Ransomware Staging GroundA compromised backup server is a high-value target for attackers who want to delete or encrypt recovery copies before deploying ransomware elsewhere

Who Is At Risk

Any organization running AhsayCBS 10.3.0 through 10.3.2 is exposed if the Replication Receiver API is reachable from an untrusted network — including the public internet, in deployments that expose AhsayCBS management interfaces for multi-site replication. Managed service providers (MSPs) offering backup-as-a-service to downstream clients carry the highest exposure, since a single compromised AhsayCBS instance can affect every client tenant it serves.


Mitigation

Immediate Actions

  • Upgrade to AhsayCBS 10.3.4 or later, which resolves the command injection in the Replication Receiver component.
  • Restrict network access to the UpdateReceivers.do endpoint and the broader Replication Receiver API to known, trusted replication peers only — never expose it to the open internet.
  • Review backup server logs for unusual requests to /rps/api/json/UpdateReceivers.do and for unexpected process spawns on the AhsayCBS host.

For MSPs and Backup Administrators

  • Treat backup infrastructure as Tier-0 — segment AhsayCBS hosts on their own restricted network zone, separate from general server infrastructure.
  • Rotate credentials stored in AhsayCBS configuration files if any evidence of unauthorized access is found.
  • Verify offline or immutable backup copies exist independent of the AhsayCBS instance, so a compromised backup server cannot also compromise your recovery path.

For Security Teams

  • Add AhsayCBS to vulnerability-scanning and asset-inventory scope if used internally or by any MSP serving your organization.
  • Monitor for the CVE's addition to CISA's KEV catalog, and treat it as a priority patch regardless of KEV status given the CVSS 10.0 score and lack of authentication required.
  • Consider a WAF or network ACL rule blocking external access to AhsayCBS replication endpoints until all instances are confirmed patched.

Key Takeaways

  1. CVE-2026-105134 is a CVSS 10.0 Critical OS command injection vulnerability in Ahsay AhsayCBS 10.3.0–10.3.2, classified under CWE-77/CWE-78.
  2. The flaw lives in the Replication Receiver API — POST /rps/api/json/UpdateReceivers.do — where the random parameter reaches a system command without adequate sanitization.
  3. No authentication, privileges, or user interaction are required, making this exploitable by any attacker who can reach the endpoint over the network.
  4. Because AhsayCBS is backup infrastructure, compromise exposes archived data and credentials for every client the instance serves — a particular risk for MSPs.
  5. AhsayCBS 10.3.4 fixes the issue. Reports on public exploit availability conflict, and the CVE is not yet in CISA's KEV catalog, but the unauthenticated, network-exploitable profile warrants immediate patching.
  6. Organizations that cannot patch immediately should restrict network access to the Replication Receiver API as an interim mitigation.

Sources