Full Report
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java"
Analysis Summary
# Vulnerability: Authentication Bypass and Remote Code Execution in AhsayCBS
## CVE Details
- **CVE ID:** CVE-2026-105133 / CVE-2026-105134
- **CVSS Score:** 5.5 (Medium) / 9.3 (Critical)
- **CWE:** Improper Authentication (CWE-287) / OS Command Injection (CWE-78)
## Affected Systems
- **Products:** AhsayCBS Backup Utility
- **Versions:** All versions prior to 10.3.4; notably, version 10.3.4 has also been reported as potentially vulnerable (zero-day status).
- **Configurations:** Systems with the management interface or Replication Receiver component exposed to the internet.
## Vulnerability Description
This threat involves a chain of two vulnerabilities:
1. **CVE-2026-105133:** An improper authentication flaw within the `checkSysPwd()` function in `com/ahsay/obs/api/ApiStructsAction.java`. This allows an attacker to bypass standard security checks.
2. **CVE-2026-105134:** An OS command injection vulnerability in the Replication Receiver component.
By chaining these, a remote unauthenticated attacker can bypass login requirements and execute arbitrary commands with the privileges of the application.
## Exploitation
- **Status:** Exploited in the wild (active campaigns observed starting Oct 7, 2026).
- **Complexity:** Low (chainable for full compromise).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Total access to backup data and system files).
- **Integrity:** High (Ability to deploy web shells and unauthorized scripts).
- **Availability:** High (Deployment of cryptominers and termination of system processes).
## Remediation
### Patches
- Vendor release notes indicate a fix in **version 10.3.4**, though recent reports suggest current versions may still be susceptible. Users should monitor for subsequent emergency updates.
### Workarounds
- **Network Segmentation:** Immediately restrict access to the AhsayCBS management interface. It should not be exposed to the public internet.
- **Access Control:** Limit access to trusted IP addresses only or require a VPN for administrative access.
## Detection
- **Indicators of Compromise (IoCs):**
- Presence of `edge.exe` in unusual directories (XMRig miner masquerading as Microsoft Edge).
- Presence of `Taskgmr.ps1` (AI-assisted PowerShell script used to kill Task Manager).
- Presence of `WinRing0x64.sys` in the `TEMP` folder (vulnerable driver used for BYOVD attacks).
- **Detection Methods:**
- Audit `certutil.exe` logs for suspicious downloads to `TEMP` directories.
- Monitor for unauthorized web shells in the AhsayCBS web directory.
- Check for anomalous CPU spikes consistent with cryptomining.
## References
- **Vendor Advisory:** hxxps[://]www[.]ahsay[.]com/en/support/help-centre/release-notes/cbs/v10.3.4
- **Researcher Analysis:** hxxps[://]www[.]huntress[.]com/blog/ahsaycbs-flaws-exploit
- **NVD Entries:** hxxps[://]nvd[.]nist[.]gov/vuln/detail/cve-2026-105133