CVE-2026-108540
Deferred Deferred - Pending Action

OpenSpug File Transfer Command Injection Vulnerability

Vulnerability report for CVE-2026-108540, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulDB

Description

A flaw has been found in OpenSpug Spug up to 3.4.0/4.0.1. This impacts an unknown function of the file /exec/transfer of the component File Transfer. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
OpenSpug Spug 3.0
OpenSpug Spug 3.1
OpenSpug Spug 3.2
OpenSpug Spug 3.3
OpenSpug Spug 3.4.0
OpenSpug Spug 4.0.0
OpenSpug Spug 4.0.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108540 is a command injection flaw in OpenSpug Spug versions up to 3.4.0/4.0.1 affecting the File Transfer component. It allows authenticated users with File Distribution permissions to execute arbitrary commands on the Spug server and managed hosts. The issue stems from improper input handling in the `dst_dir` and `data.host[1]` parameters, enabling shell command injection via special characters like semicolons.

Detection Guidance

Check for unauthorized file transfers or unexpected command executions in Spug logs. Inspect network traffic for suspicious rsync or shell commands involving the dst_dir or data.host[1] parameters. Look for files created outside expected directories or hosts.

Impact Analysis

This vulnerability allows attackers to execute arbitrary commands on the Spug server and any managed hosts they have access to. This could lead to full compromise of the platform, unauthorized file creation, data theft, or further lateral movement within the network. The impact includes potential system takeover and unauthorized access to sensitive data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. It may result in data breaches, unauthorized disclosures, and failure to maintain adequate security controls, potentially leading to regulatory penalties and loss of compliance certifications.

Mitigation Strategies

Update Spug to the latest patched version. Disable the File Distribution feature if not needed. Implement strict input validation for dst_dir and data.host parameters. Restrict permissions for File Distribution to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108540. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart