CVE-2026-108540 | OpenSpug up to 3.4.0/4.0.1 File Transfer /exec/transfer os command injection (Issue 10)
A vulnerability, which was classified as very critical, was found in OpenSpug Spug up to 3.4.0/4.0.1. This impacts an unknown function of the file /exec/transfer of the component File Transfer. Executing a manipulation can lead to os command injection.
The identification of this vulnerability is CVE-2026-108540. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More