Back threataft.com OpenSpug Spug CVE-2026-108540 - CVSS 9.9 RCE ThreatAft / 6h Attribute Value CVE CVE-2026-108540 CVSS 3.1 9.9 (Critical) CVSS 4.0 9.4 (Critical) CWE CWE-78 OS Command Injection / CWE-77 Command Injection Attack Vector Remote, low privileges required Affected Component /exec/transfer — File Transfer Exploitation Public PoC available Vendor Response None A public proof-of-concept exploit exists and the vendor has not responded to disclosure.
An OS command injection flaw in OpenSpug Spug allows remote attackers to execute arbitrary commands on the server. CVE-2026-108540 (CVSS 3.1 9.9) affects Spug through versions 3.4.0 and 4.0.1, an open-source automation operations platform for small and medium enterprises. A public proof-of-concept exploit exists and the vendor has not responded to disclosure. No patch is available.
📌 TL;DR — OpenSpug Spug CVE-2026-108540
What: CVE-2026-108540 — OS command injection in the /exec/transfer endpoint of OpenSpug Spug through 3.4.0/4.0.1. CVSS 3.1 9.9 (Critical). Who's affected: Spug versions 3.0, 3.1, 3.2, 3.3, 3.4.0, 4.0.0, and 4.0.1. Impact: Remote command execution on the Spug host. Pivot point to managed servers, credentials, and CI/CD pipelines. Exploit status: Public proof-of-concept available. Exploitation considered easy. Fix: No patch. Vendor did not respond. Restrict network access immediately.
Public Exploit Available: A proof-of-concept exploit was published alongside the disclosure. VulDB classifies the exploitation as easy and notes the attack may be launched remotely.
No Patch and No Vendor Response: The vendor was contacted before disclosure but did not respond. No fixed version is available and no countermeasures are documented.
High-Value Pivot Point: Spug is an automation operations platform. Deployments typically hold SSH keys, host credentials, and automation privileges for managed infrastructure. A compromised Spug instance becomes a pivot into everything it manages.
Broad Version Exposure: The vulnerability affects seven versions spanning the 3.x and 4.x branches, including the latest releases at the time of disclosure.
Internet-Exposed Deployments at Risk: The /exec/transfer endpoint is remotely reachable. Any Spug instance exposed to untrusted networks should be treated as a target.
CVE-2026-108540 is classified as OS Command Injection (CWE-78) and Command Injection (CWE-77) . The flaw resides in the /exec/transfer endpoint of the File Transfer component.
Root cause: The product constructs all or part of an OS command using externally-influenced input from an upstream component but fails to neutralize special elements that could modify the intended command when it is sent to a downstream component.
Attacker sends a crafted request to the /exec/transfer endpoint.
The request contains shell metacharacters in a parameter handled by the File Transfer component.
The input is passed into a shell command without adequate neutralization.
Arbitrary OS commands execute on the Spug host.
CVSS 3.1 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:C — network-reachable, low privileges required, no user interaction, scope changed, high impact across confidentiality, integrity, and availability.
A public proof-of-concept exploit is available. VulDB lists the exploit as accessible and classifies the attack as easy. The exploit is declared as proof-of-concept. The vendor was contacted before disclosure but did not respond. No official patch or vendor workaround exists.
No workarounds: The advisory states no information possible countermeasures is known and suggests replacing the affected object with an alternative product.
Remove internet exposure. Place Spug behind a VPN or zero-trust access layer. Block /exec/* at the reverse proxy or WAF if remote access is required.
Remove internet exposure. Place Spug behind a VPN or zero-trust access layer. Block /exec/* at the reverse proxy or WAF if remote access is required.
Hunt for exploitation. Audit Spug access logs for requests to /exec/transfer containing shell metacharacters ( ; , | , ` , $() ). Inspect process trees and outbound connections from the Spug host.
Hunt for exploitation. Audit Spug access logs for requests to /exec/transfer containing shell metacharacters ( ; , | , ` , $() ). Inspect process trees and outbound connections from the Spug host.
Rotate credentials. Any SSH keys, API tokens, or host credentials stored in or used by Spug must be rotated — assume exposure.
Rotate credentials. Any SSH keys, API tokens, or host credentials stored in or used by Spug must be rotated — assume exposure.
Isolate and monitor. Segment the Spug host from managed infrastructure. Enable command-line and file-integrity monitoring.
Isolate and monitor. Segment the Spug host from managed infrastructure. Enable command-line and file-integrity monitoring.
Compensating Controls (if patching is delayed)
ThreatAft defensive guidance, not official vendor advice.
Block the endpoint at the reverse proxy. Add a rule to deny or return 403 for /exec/transfer .
Network segmentation. Isolate Spug from managed servers and sensitive infrastructure.
Consider replacement. Evaluate maintained alternatives given the vendor's non-response and the absence of a patch.
CIRCL — Vulnerability Database
VulDB — Vulnerability Database
If you run OpenSpug Spug through 3.4.0 or 4.0.1, assume it is exploitable if the File Transfer endpoint is reachable from an untrusted network. A public exploit exists, the vendor has not responded, and no patch is available. Spug is frequently deployed with broad host access and credentials — successful exploitation grants a pivot point to managed servers, secrets stores, and CI/CD pipelines.
The practical priority is network restriction: remove internet exposure, block /exec/transfer at the reverse proxy, and audit for exploitation indicators. Given the public PoC, opportunistic scanning should be expected within hours to days.
Remove internet exposure. Block /exec/transfer at the reverse proxy. Audit logs for shell metacharacters. Rotate credentials stored in Spug.
— The ThreatAft Security Team
ThreatAft is an independent security publication. This analysis is based on research published by CVE.org, CIRCL, and VulDB as of October 2026. Vulnerability information is time-sensitive; always refer to official sources for the most current guidance.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
