AI description
CVE-2026-105133 is an improper authentication vulnerability affecting AhsayCBS, a centralized cloud backup server management console developed by Ahsay Systems and widely used by managed service providers (MSPs). The flaw resides in the `checkSysPwd` function within the `com/ahsay/obs/api/ApiStructsAction.java` file of the application's API component. By manipulating the `random` argument, a remote attacker can bypass authentication mechanisms to gain unauthorized access to the system. In real-world attacks, threat actors have been observed chaining CVE-2026-105133 with another vulnerability, CVE-2026-105134, to achieve unauthenticated remote code execution. This exploit chain allows attackers to deploy Java Server Page (JSP) webshells and install XMRig cryptocurrency miners disguised as legitimate system processes like Microsoft Edge. While initial reports indicated the issue was resolved in version 10.3.4, security researchers have noted that this version may still be susceptible, prompting recommendations to restrict access to the management interface.
- Description
- A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component.
- Source
- cna@vuldb.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 5.5
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
CVSS 3.1
- Type
- Secondary
- Base score
- 7.3
- Impact score
- 3.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Severity
- HIGH
CVSS 2.0
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
- cna@vuldb.com
- CWE-287
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
4
⚠️ Two AhsayCBS backup-server flaws are exploited in the wild: CVE-2026-105133 (auth bypass) + CVE-2026-105134 (RCE as SYSTEM). Huntress saw webshells and XMRig miners at 5+ orgs. Latest 10.3.4 is still affected. Lock the admin UI to trusted IPs/VPN. #ZeroDay #CVE #infosec ht
@BursaMatus
11 Oct 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
💢AhsayCBS açığı CVE-2026-105134 artık aktif saldırılarda kullanılıyor: 10.3.4 sürümü de savunmasız Huntress'ın raporuna göre saldırganlar 7 Ekim 23:20 UTC'den bu yana kimlik doğrulama açığı CVE-2026-105133 ile komut enjeksiyonu açığı CVE-2026-105134'
@trsiberyazilim
10 Oct 2026
377 Impressions
1 Retweet
37 Likes
0 Bookmarks
0 Replies
0 Quotes
No patch yet. Attackers are chaining two AhsayCBS backup flaws, CVE-2026-105133 (auth bypass) and CVE-2026-105134 (command injection), to drop webshells and an XMRig miner named edge.exe. Huntress says the latest 10.3.4 is affected. Limit the admin UI to trusted IPs. #MSP #CVE h
@ai4cybersec
10 Oct 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚔️ AHSAYCBS ZERO-DAY EXPLOITS! Attackers chain auth bypass (CVE-2026-105133) & command injection (CVE-2026-105134) for SYSTEM RCE & evasive XMRig mining. Read full Blog: https://t.co/iAwNSgGCFy #Hacktober #CyberAwareness #sh3llc0d3 #shellcode #ZeroDay
@sh3ll_c0d3
10 Oct 2026
67 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
AhsayCBS backup servers under attack: CVE-2026-105133 (auth bypass) plus CVE-2026-105134 (command injection) gives SYSTEM RCE. Attackers drop JSP webshells and XMRig posing as edge.exe. Limit the console to trusted IPs and hunt for compromise. #infosec https://t.co/Ioj1xVcmzw
@V0iD_0daY
10 Oct 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🐦 🚨 AhsayCBS backup software under active attack: CVE-2026-105134 (CVSS 10.0) chained with CVE-2026-105133 for unauthenticated RCE as SYSTEM, webshells + XMRig dropped. Patch 10.3.4 available. Also actively exploited: Atlassian CVE-2026-21589 (CVSS 9.3). #infosec #CVE #0da
@ita_ipo
10 Oct 2026
58 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Threat actors exploited AhsayCBS flaws CVE-2026-105133 and CVE-2026-105134 to drop webshells and XMRig miners, with a call to update to 10.3.4 and restrict access now. https://t.co/DXz4dR3EHh
@Cyber_O51NT
10 Oct 2026
607 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
CVE-2026-105134 (CVSS 9.3) chained with CVE-2026-105133 in AhsayCBS is actively exploited as a zero-day, dropping webshells and XMRig as edge.exe. Hunt TEMP for WinRing0x64.sys and Taskgmr.ps1. #DFIR_Radar https://t.co/C1WzYLSEBi
@DFIR_Radar
10 Oct 2026
141 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Zero-day chain CVE-2026-105133 and CVE-2026-105134 in AhsayCBS 10.3.4 drops JSP webshells and XMRig as edge.exe, persisting via MicrosoftEdgeUpdateSvc. #DFIR_Radar https://t.co/Uh5nr97V1h
@DFIR_Radar
10 Oct 2026
128 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
バックアップ管理者には、復旧の頼みまで狙われる嫌な話だ。 HuntressはAhsayCBSのCVE-2026-105133/CVE-2026-105134の実悪用を観測。認証回避とOS command injectionを連鎖させ、認証不要のRCEにつなげる攻撃だ。同社は10月8日
@connect24h
10 Oct 2026
626 Impressions
0 Retweets
5 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical Unpatched AhsayCBS Vulnerabilities (#CVE-2026-105133 & #CVE-2026-105134): Active Exploitation and Hardening Guide + Video -Prediction: 📈 1 Positive | 📉 1 Negative https://t.co/tTdJmGwKdr Educational Purposes!
@UndercodeUpdate
10 Oct 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are chaining CVE-2026-105133 + CVE-2026-105134 in AhsayCBS to bypass auth, drop web shells and deploy XMRig miners. Patch and hunt now. #Cybersecurity #InfoSec #CVE https://t.co/iWGhb2KZAL
@CyberWorldOps
9 Oct 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes