Remote Code Execution Vulnerability in Spug by OpenSpug
CVE-2026-90770
8.7HIGH
What is CVE-2026-90770?
Spug through version 3.4.0 contains a vulnerability in the ping_check function that allows authenticated users with monitor permissions to execute arbitrary commands on the server. By manipulating monitor address inputs via the /monitor/run_test/ endpoint, attackers can inject shell metacharacters without proper input validation, leading to unauthorized command execution as the Spug process user. This poses significant risks to the integrity and security of the affected systems.
Affected Version(s)
spug 0 <= 3.4.0
