CVE-2026-90770: Openspug Spug
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/run_test/ endpoint to execute arbitrary commands as the Spug process user.
Affected products
- Openspug Spug: up to and including 3.4.0
Published 2026-09-13. Last modified 2026-09-23.