Skip to finding
important · Backup infrastructure

AhsayCBS records describe unauthenticated command injection in the Replication Receiver API.

Affects

AhsayCBS, a self-hosted enterprise backup-management and replication server for Windows and Unix-like systems.

A network client can submit a crafted random parameter to UpdateReceivers.do over the Replication Receiver HTTP or HTTPS service, commonly on port 80 or 443.

Detail and 6 sources

We could not verify the cited exploit or determine the resulting process identity on Windows and Linux from a primary publication.

Chain to watch
Reach the Replication Receiver API without authenticating.→↓Submit a crafted random parameter to UpdateReceivers.do.→↓Determine whether the resulting command executes and under which service identity.→↓The cited exploit and the command’s execution identity remain unverified.
Unverified chainRetrieve the cited exploit, replay it in an authorized AhsayCBS 10.3.2-or-earlier lab, and record the process identity on Windows and Linux.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, October 5, 2026