Sceawere

Vulnerability Detail

CVE-2026-105133UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AhsayCBS Improper Authentication Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
2h ago
Vendor
Ahsay
Product
AhsayCBS
Attack Type
Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-04T07:16:33.087Z",
  "pubdate": "2026-10-04T07:16:33.087Z",
  "executiveSummary": "Ahsay AhsayCBS versions up to 10.3.2 are susceptible to an improper authentication vulnerability within the API component.\nThe vulnerability arises from insufficient validation of the 'random' argument within the 'checkSysPwd' function, which resides in 'com/ahsay/obs/api/ApiStructsAction.java'.\nThis flaw allows a remote, unauthenticated attacker to bypass authentication mechanisms by manipulating the specified input parameter.\nSuccessful exploitation permits unauthorized access to the application, potentially leading to full compromise of the affected system.\nGiven that the exploit is publicly available, the risk to unpatched installations is high, necessitating immediate remediation to prevent unauthorized system access and potential data exfiltration or administrative control.",
  "technicalDetails": "The vulnerability is located in the 'checkSysPwd' function within the 'com/ahsay/obs/api/ApiStructsAction.java' file of the AhsayCBS API component.\nThe root cause is improper authentication logic regarding the handling of the 'random' argument. The application fails to adequately validate or bind the 'random' parameter during the authentication verification sequence, allowing an attacker to supply crafted input that bypasses the intended credential validation process.\nExploitation is conducted remotely via the network, requiring no prior authentication. An attacker can craft an HTTP request targeting the vulnerable API endpoint and manipulate the 'random' argument. By providing specifically engineered input to this parameter, the attacker forces the 'checkSysPwd' function to evaluate the authentication attempt as successful, regardless of the validity of the provided credentials.\nThe attack flow proceeds as follows: 1) The attacker identifies the vulnerable API endpoint associated with the 'ApiStructsAction' class. 2) The attacker initiates an authentication request and injects a manipulated 'random' value into the API request parameters. 3) The 'checkSysPwd' function processes this input without robust verification or cryptographic binding. 4) Due to the lack of proper input validation, the function returns a successful authentication state to the calling component. 5) The system grants the attacker an authenticated session context.\nThis vulnerability effectively circumvents the authentication layer entirely, providing the attacker with access to the privileges associated with the targeted user account. If the affected endpoint or the resulting session context facilitates administrative actions, the attacker can leverage this improper authentication to perform unauthorized administrative operations within AhsayCBS.\nPost-exploitation, the attacker can maintain unauthorized access, manage backup configurations, or access sensitive data stored or processed by the AhsayCBS application. Because the exploit is public, the attack vector is trivial to replicate, posing a significant risk to confidentiality, integrity, and availability of the affected backup server instances."
}
CVE-2026-105133: AhsayCBS Improper Authentication Vulnerability (HIGH Severity, CVSS: 7.3) | Sceawere