Sceawere
Vulnerability Detail
CVE-2026-108546UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Spotweb OS Command Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- spotweb
- Product
- spotweb
- Attack Type
- Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with shell metacharacters in the title, which are substituted unescaped for $SPOTTITLE and passed to exec() when a user downloads the spot, running commands as the Spotweb PHP process.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-10T15:16:57.573Z",
"pubdate": "2026-10-10T15:16:57.573Z",
"executiveSummary": "Spotweb versions through 1.5.8 are susceptible to an OS command injection vulnerability located within the runcommand NZB handler. The flaw arises from the improper handling of user-supplied input contained within spot titles.\nBy crafting a malicious spot title containing shell metacharacters, a remote attacker can achieve arbitrary command execution under the context of the user running the Spotweb PHP process.\nThis vulnerability is critical as it permits remote code execution (RCE) without requiring prior authentication, leveraging the inherent nature of Usenet content distribution. Since the application fails to sanitize or escape data before processing, any user capable of publishing spots to the Usenet network can trigger the injection.\nSuccessful exploitation compromises the server hosting the Spotweb instance, potentially leading to unauthorized data access, system persistence, or lateral movement within the network. The impact is dictated by the privileges assigned to the web server process, making it a high-risk security concern for administrators.",
"technicalDetails": "The vulnerability resides in the interaction between the Spotweb application and the underlying operating system during the processing of NZB files. Specifically, the component responsible for the 'runcommand' NZB handler fails to perform adequate input validation or sanitization on the data retrieved from spot titles.\nThe root cause is the direct, unescaped interpolation of the $SPOTTITLE variable into a command string passed to the exec() PHP function. In the execution flow, when a user initiates a download for a specific spot, the application fetches the metadata associated with that spot, including the title, from the Usenet feed. This title string is then concatenated directly into a shell command template designed to automate post-processing or external handling of the NZB file.\nBecause the title field is controlled by the spot publisher on Usenet, an attacker can inject arbitrary shell metacharacters—such as semicolons (;), backticks (`), or pipes (|)—followed by malicious system commands. When the Spotweb PHP process executes the handler, the operating system shell interprets these metacharacters as command separators or subshell execution directives, effectively terminating the intended command and launching the attacker's payload.\nThe attack flow follows these steps: 1) The attacker publishes a malicious spot to Usenet with a title containing a command injection payload. 2) A victim or automated system using Spotweb indexes this spot. 3) The victim triggers the download handler for the malicious spot. 4) The Spotweb application retrieves the tainted title string. 5) The runcommand handler passes the unescaped string to the system shell via exec(). 6) The shell executes the injected command with the privileges of the web server user.\nThis vulnerability affects Spotweb through version 1.5.8. Exploitation does not require authentication to the target Spotweb instance, as the trigger is the processing of external content. Post-exploitation, the attacker gains the ability to execute arbitrary code, which can result in full server compromise, exfiltration of configuration files (such as database credentials), or the installation of further persistent backdoors."
}