CVE-2026-107459: Openfind|SecuShare Pro - OS Command Injection
The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
For Customized edition, verify the current system version and provide the version number to Openfind so it can provide the corresponding security patch; Standard edition customers should contact the Openfind technical service team for assistance with the update.
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
Unauthenticated remote attackers can exploit it. No prior account or authentication is required.
What level of access could an attacker obtain?
An attacker can inject and execute arbitrary OS commands on the affected server. The reported impact includes high confidentiality, integrity, and availability impact.
Is user interaction required for exploitation?
No. The vulnerability is rated with no user interaction required and low attack complexity.