Description
The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
Published: 2026-10-08
Score: 9.3 Critical
EPSS: 1.5% Low
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Cloud edition: All MailCloud (including EaaS) environments have been fully updated. The service is not affected and no further action is required. Standard edition: SecuShare Pro customers should contact the Openfind technical service team for assistance with the update. Customized edition: Please verify the current system version and provide the version number to Openfind, who will provide the corresponding security patch.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 06:00:00 +0000

Type Values Removed Values Added
Description The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
Title Openfind|SecuShare Pro - OS Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-10-08T13:56:25.892Z

Reserved: 2026-10-08T05:38:23.283Z

Link: CVE-2026-107459

cve-icon Vulnrichment

Updated: 2026-10-08T13:56:20.573Z

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:42.000

Modified: 2026-10-08T14:16:47.503

Link: CVE-2026-107459

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T18:15:14Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')