← Vulnerability feed

Vulnerability record · CVE-2022-37027 · published 21 September 2022

CVE-2022-37027: Ahsay cloud backup suite argument injection vulnerability

Ahsay · Cloud Backup Suite

Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.

7.2 CVSS 3.1 High EPSS 22% · top 2.4% CWE-88 · Argument injection
7.2CVSS 3.1 base score
22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-37027 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-5846Ahsay cloud backup suite unrestricted file upload vulnerabilityAn insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with t…EPSS 1.4%8.8CVE-2019-10267Ahsay Cloud Backup Suite unrestricted file upload leads to code executionAhsay Cloud Backup Suite 8.1.0.50 allows an authenticated user to upload a file into any directory on the server. Because uploaded JSP files are exec…EPSS 75%analysed7.5CVE-2019-10265Ahsay cloud backup suite path traversal vulnerabilityAn issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. On the /cbs/system/ShowAdvanced.do "File Explorer" screen, it is possible to cha…EPSS 2.5%7.5CVE-2019-10266Ahsay cloud backup suite xml external entity (xxe) vulnerabilityAn issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the …EPSS 13%7.2CVE-2019-10264Ahsay cloud backup suite xml external entity (xxe) vulnerabilityAn issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. With a valid administrator account, the "Move / Import / Export Users" screen ha…EPSS 1.3%6.1CVE-2019-10263Ahsay cloud backup suite cross-site scripting vulnerabilityAn issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When creating a trial account, it is possible to inject XSS in the Alias field, …EPSS 0.83%9.2CVE-2026-86060MikroTik RouterOS SSH login argument injection privilege escalationRouterOS mishandles arguments in the SSH login path when a username begins with a prohibited character, allowing the trusted policy mask to be altere…KEVEPSS 1.8%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2022-37027), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.