OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-105133

HIGH · CVSS 7.3 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-04 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A vulnerability in AhsayCBS versions up to 10.3.2 allows for improper authentication through manipulation of the 'random' argument in the checkSysPwd function, potentially enabling remote exploitation. Organizations using affected versions of AhsayCBS should prioritize upgrading to version 10.3.4 to mitigate this high-severity risk, as the exploit is now publicly available. Immediate action is essential to protect sensitive data and maintain system integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105133
Severity
HIGH
CVSS
7.3
EPSS
0.38%
Java

Original NVD Description

A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component.