CVE-2026-105133

Published Oct 4, 2026

Last updated 5 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-105133 is an improper authentication vulnerability affecting AhsayCBS, a centralized cloud backup server management console developed by Ahsay Systems and widely used by managed service providers (MSPs). The flaw resides in the `checkSysPwd` function within the `com/ahsay/obs/api/ApiStructsAction.java` file of the application's API component. By manipulating the `random` argument, a remote attacker can bypass authentication mechanisms to gain unauthorized access to the system. In real-world attacks, threat actors have been observed chaining CVE-2026-105133 with another vulnerability, CVE-2026-105134, to achieve unauthenticated remote code execution. This exploit chain allows attackers to deploy Java Server Page (JSP) webshells and install XMRig cryptocurrency miners disguised as legitimate system processes like Microsoft Edge. While initial reports indicated the issue was resolved in version 10.3.4, security researchers have noted that this version may still be susceptible, prompting recommendations to restrict access to the management interface.

Description
A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component.
Source
cna@vuldb.com
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
5.5
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Secondary
Base score
7.3
Impact score
3.4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity
HIGH

CVSS 2.0

Type
Secondary
Base score
7.5
Impact score
6.4
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

cna@vuldb.com
CWE-287

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

4

  1. ⚠️ Two AhsayCBS backup-server flaws are exploited in the wild: CVE-2026-105133 (auth bypass) + CVE-2026-105134 (RCE as SYSTEM). Huntress saw webshells and XMRig miners at 5+ orgs. Latest 10.3.4 is still affected. Lock the admin UI to trusted IPs/VPN. #ZeroDay #CVE #infosec ht

    @BursaMatus

    11 Oct 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 💢AhsayCBS açığı CVE-2026-105134 artık aktif saldırılarda kullanılıyor: 10.3.4 sürümü de savunmasız Huntress'ın raporuna göre saldırganlar 7 Ekim 23:20 UTC'den bu yana kimlik doğrulama açığı CVE-2026-105133 ile komut enjeksiyonu açığı CVE-2026-105134'

    @trsiberyazilim

    10 Oct 2026

    377 Impressions

    1 Retweet

    37 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. No patch yet. Attackers are chaining two AhsayCBS backup flaws, CVE-2026-105133 (auth bypass) and CVE-2026-105134 (command injection), to drop webshells and an XMRig miner named edge.exe. Huntress says the latest 10.3.4 is affected. Limit the admin UI to trusted IPs. #MSP #CVE h

    @ai4cybersec

    10 Oct 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. ⚔️ AHSAYCBS ZERO-DAY EXPLOITS! Attackers chain auth bypass (CVE-2026-105133) & command injection (CVE-2026-105134) for SYSTEM RCE & evasive XMRig mining. Read full Blog: https://t.co/iAwNSgGCFy #Hacktober #CyberAwareness #sh3llc0d3 #shellcode #ZeroDay

    @sh3ll_c0d3

    10 Oct 2026

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. AhsayCBS backup servers under attack: CVE-2026-105133 (auth bypass) plus CVE-2026-105134 (command injection) gives SYSTEM RCE. Attackers drop JSP webshells and XMRig posing as edge.exe. Limit the console to trusted IPs and hunt for compromise. #infosec https://t.co/Ioj1xVcmzw

    @V0iD_0daY

    10 Oct 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🐦 🚨 AhsayCBS backup software under active attack: CVE-2026-105134 (CVSS 10.0) chained with CVE-2026-105133 for unauthenticated RCE as SYSTEM, webshells + XMRig dropped. Patch 10.3.4 available. Also actively exploited: Atlassian CVE-2026-21589 (CVSS 9.3). #infosec #CVE #0da

    @ita_ipo

    10 Oct 2026

    58 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Threat actors exploited AhsayCBS flaws CVE-2026-105133 and CVE-2026-105134 to drop webshells and XMRig miners, with a call to update to 10.3.4 and restrict access now. https://t.co/DXz4dR3EHh

    @Cyber_O51NT

    10 Oct 2026

    607 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  8. CVE-2026-105134 (CVSS 9.3) chained with CVE-2026-105133 in AhsayCBS is actively exploited as a zero-day, dropping webshells and XMRig as edge.exe. Hunt TEMP for WinRing0x64.sys and Taskgmr.ps1. #DFIR_Radar https://t.co/C1WzYLSEBi

    @DFIR_Radar

    10 Oct 2026

    141 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. Zero-day chain CVE-2026-105133 and CVE-2026-105134 in AhsayCBS 10.3.4 drops JSP webshells and XMRig as edge.exe, persisting via MicrosoftEdgeUpdateSvc. #DFIR_Radar https://t.co/Uh5nr97V1h

    @DFIR_Radar

    10 Oct 2026

    128 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. バックアップ管理者には、復旧の頼みまで狙われる嫌な話だ。 HuntressはAhsayCBSのCVE-2026-105133/CVE-2026-105134の実悪用を観測。認証回避とOS command injectionを連鎖させ、認証不要のRCEにつなげる攻撃だ。同社は10月8日

    @connect24h

    10 Oct 2026

    626 Impressions

    0 Retweets

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🚨 Critical Unpatched AhsayCBS Vulnerabilities (#CVE-2026-105133 & #CVE-2026-105134): Active Exploitation and Hardening Guide + Video -Prediction: 📈 1 Positive | 📉 1 Negative https://t.co/tTdJmGwKdr Educational Purposes!

    @UndercodeUpdate

    10 Oct 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Attackers are chaining CVE-2026-105133 + CVE-2026-105134 in AhsayCBS to bypass auth, drop web shells and deploy XMRig miners. Patch and hunt now. #Cybersecurity #InfoSec #CVE https://t.co/iWGhb2KZAL

    @CyberWorldOps

    9 Oct 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes