HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-105486 — A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the functio...

·Source: NIST NVD

Updated:

Executive Summary

A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 8.0-d0 mitigates this issue. The patch is named bb5fde228f4ca5bd26d9

Analysis

A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 8.0-d0 mitigates this issue. The patch is named bb5fde228f4ca5bd26d96368b61f6e0c21df51df. The affected component should be upgraded. CVSS Score: 7.3. Published: 2026-10-06T02:17:04.213.

Indicators of Compromise (2)

SHA-1 (1)
bb5fde228f4ca5bd26d96368b61f6e0c21df51df
CVE (1)
CVE-2026-105486
Source Attribution

Originally published by NIST NVD on Oct 6, 2026. Verified by: NIST.

Related Threats