OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105486

HIGH · CVSS 7.3 EPSS 0.50% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A vulnerability in the System API of F5's OSSRS versions up to 7.0-a1 allows for remote exploitation due to missing authentication in the systemAPI.Run function. This high-severity flaw could lead to unauthorized access and manipulation of the system. Organizations using affected versions should prioritize upgrading to version 8.0-d0 to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105486
Severity
HIGH
CVSS
7.3
EPSS
0.50%
F5

Original NVD Description

A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 8.0-d0 mitigates this issue. The patch is named bb5fde228f4ca5bd26d96368b61f6e0c21df51df. The affected component should be upgraded.