---
id: CVE-2026-105133
title: A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2
summary: >-
  A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the
  function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of
  the component API. Performing a manipulation of the argument random results in
  impr…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-287
vendor: Ahsay
product: AhsayCBS
affected:
  - AhsayCBS 10.3.0
  - AhsayCBS 10.3.1
  - AhsayCBS 10.3.2
published: '2026-10-04'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T07:16:33.087'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105133'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-105133'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/942688'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413350'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413350/cti'
    label: cna@vuldb.com
  - url: 'https://www.ahsay.com/en/support/help-centre/release-notes/cbs/v10.3.4'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-04T06:55:02.309Z'
epss: 0.00383
epssPercentile: 0.30028
---

## Overview

A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
