CVE WATCH / VULNERABILITY DETAIL

CVE-2026-108546

HIGHCVSS 7.5NVD feed

Published 10 October 2026 · tracked since 11 October 2026

Description

Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with shell metacharacters in the title, which are substitute

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-108546 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-108546

HIGHCVSS 7.5NVD feed

Published 10 October 2026 · tracked since 11 October 2026

Description

Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with shell metacharacters in the title, which are substitute

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]