PatchSiren cyber security CVE debrief
CVE-2026-107780 dromara CVE debrief
CVE-2026-107780 is a critical unauthenticated OS command injection vulnerability in the Dromara Skyeye service, specifically via the /post/TtsController/textToSpeech endpoint's format parameter. This vulnerability allows attackers to execute commands as the Skyeye service account on Windows systems by injecting a single quote into the format parameter to break out of the PowerShell string.
- Vendor
- dromara
- Product
- skyeye
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Skyeye deployments, especially those exposed to the internet, should assess their exposure and prioritize patching or applying mitigations. Security teams should monitor for suspicious activity and implement compensating controls.
Why it matters
CVE-2026-107780 is a critical vulnerability in Dromara Skyeye that allows unauthenticated OS command injection. Defenders should prioritize verifying exposure, applying patches, and monitoring for suspicious activity.
- Verify exposure of Skyeye deployments to unauthenticated OS command injection
- Assess and apply patches or mitigations to prevent exploitation
- Monitor for suspicious activity indicating potential exploitation attempts
- Implement compensating controls such as WAF rules to detect and prevent exploitation
Technical summary
The vulnerability exists in the /post/TtsController/textToSpeech endpoint of Dromara Skyeye, allowing unauthenticated attackers to inject OS commands via the format parameter. This is achieved by injecting a single quote to break out of the PowerShell string, enabling command execution as the Skyeye service account on Windows. Affected product deployments should be verified for exposure, especially those accessible from the internet, and patches or mitigations should be applied as available. The vulnerability has a CVSS score of 9.3 and is considered critical.
Defensive priority
Defenders should prioritize verifying exposure of Skyeye deployments, especially those accessible from the internet, and apply patches or mitigations as available.
Recommended defensive actions
- Verify exposure of Dromara Skyeye deployments, especially those accessible from the internet
- Review and apply patches or mitigations as available from the vendor
- Monitor for suspicious activity on affected systems
- Implement compensating controls such as WAF rules to detect and prevent exploitation attempts
- Review asset inventory to identify potentially affected systems
- Plan and schedule vendor-supported updates or mitigations through normal change control
- Track exceptions and retest remediated assets to ensure successful patching
Evidence notes
The CVE record and source item provide details on the vulnerability, including its existence in Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321. However, specific details about exploitation, impact, and remediation are limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107780 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107780
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107780 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107780
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Dromara Skyeye Unauthenticated OS Command Injection via textToSpeech format Parameter
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107780.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/dromara/skyeye/issues/29
Supplemental source - issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/dromara/skyeye/blob/003549ae5615bd114ba5bb8ddf6a8e8ead97c321/skyeye-promote/skyeye-common/src/main/java/com/skyeye/common/service/impl/TtsServiceImpl.java
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/dromara/skyeye
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/dromara-skyeye-unauthenticated-os-command-injection-via-texttospeech-format-parameter
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.