CVE-2026-108546
Received Received - Intake

OS Command Injection in Spotweb via Malicious Spot Titles

Vulnerability report for CVE-2026-108546, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with shell metacharacters in the title, which are substituted unescaped for $SPOTTITLE and passed to exec() when a user downloads the spot, running commands as the Spotweb PHP process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
spotweb spotweb 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an OS command injection flaw in Spotweb versions up to 1.5.8. It occurs in the runcommand NZB handler where attacker-controlled spot titles with shell metacharacters are passed unescaped to PHP's exec() function via the $SPOTTITLE variable. When a user downloads the malicious spot, the command executes with the privileges of the Spotweb PHP process.

Detection Guidance

Check Spotweb logs for unusual command execution patterns or errors in Services_NzbHandler_Runcommand.php. Look for spots with titles containing shell metacharacters like semicolons, quotes, or command substitutions. Inspect downloaded NZB files for malicious titles referencing $SPOTTITLE in runcommand integrations.

Impact Analysis

An attacker could execute arbitrary commands on your system with the privileges of the Spotweb PHP process. This may allow access to system configuration, database credentials, or local network resources. The attack requires an attacker to post a malicious spot and a user to download it.

Compliance Impact

This vulnerability could lead to unauthorized command execution on the host system running Spotweb, potentially exposing sensitive data such as database credentials or system configurations. If exploited, it may violate GDPR by enabling unauthorized access to personal data or HIPAA by compromising protected health information, depending on the data processed by the application.

Mitigation Strategies

Upgrade Spotweb to a patched version if available. If not, apply a temporary fix by modifying Services_NzbHandler_Runcommand.php to wrap $SPOTTITLE in escapeshellarg() before passing it to exec(). Disable the runcommand NZB handler if unused. Restrict post_spot permissions to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108546. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart