important · Backup infrastructure
AhsayCBS records describe unauthenticated command injection in the Replication Receiver API.
Affects
AhsayCBS, a self-hosted enterprise backup-management and replication server for Windows and Unix-like systems.
A network client can submit a crafted random parameter to UpdateReceivers.do over the Replication Receiver HTTP or HTTPS service, commonly on port 80 or 443.
Detail and 6 sources
We could not verify the cited exploit or determine the resulting process identity on Windows and Linux from a primary publication.
Chain to watch
Reach the Replication Receiver API without authenticating.→↓Submit a crafted random parameter to UpdateReceivers.do.→↓Determine whether the resulting command executes and under which service identity.→↓The cited exploit and the command’s execution identity remain unverified.
Unverified chainRetrieve the cited exploit, replay it in an authorized AhsayCBS 10.3.2-or-earlier lab, and record the process identity on Windows and Linux.
Sources
ResearchCVE-2026-105134: Ahsay AhsayCBS: A flaw has been found in Ahsay AhsayCBS up to 10.3.2 | Rapid7 Vulnerability DatabaseResearchUpdateReceivers | Ahsay BackupResearchReplication | Ahsay BackupResearchAhsayCBS (DIY) v10.3.4 Release Notes (05-Aug-2026) | Ahsay BackupCode / PoCA flaw has been found in Ahsay AhsayCBS up to 10.3.2.... · CVE-2026-105134 · GitHub Advisory Database · GitHubSecondaryAhsayCBS Replication Receiver reportedly exposes unauthenticated command execution