Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Cloud edition: All MailCloud (including EaaS) environments have been fully updated. The service is not affected and no further action is required. Standard edition: SecuShare Pro customers should contact the Openfind technical service team for assistance with the update. Customized edition: Please verify the current system version and provide the version number to Openfind, who will provide the corresponding security patch.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server. | |
| Title | Openfind|SecuShare Pro - OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-10-08T13:56:25.892Z
Reserved: 2026-10-08T05:38:23.283Z
Link: CVE-2026-107459
Updated: 2026-10-08T13:56:20.573Z
Status : Received
Published: 2026-10-08T06:16:42.000
Modified: 2026-10-08T14:16:47.503
Link: CVE-2026-107459
No data.
OpenCVE Enrichment
Updated: 2026-10-08T08:15:03Z