PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107780 dromara CVE debrief

CVE-2026-107780 is a critical unauthenticated OS command injection vulnerability in the Dromara Skyeye service, specifically via the /post/TtsController/textToSpeech endpoint's format parameter. This vulnerability allows attackers to execute commands as the Skyeye service account on Windows systems by injecting a single quote into the format parameter to break out of the PowerShell string.

Vendor
dromara
Product
skyeye
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for Skyeye deployments, especially those exposed to the internet, should assess their exposure and prioritize patching or applying mitigations. Security teams should monitor for suspicious activity and implement compensating controls.

Why it matters

CVE-2026-107780 is a critical vulnerability in Dromara Skyeye that allows unauthenticated OS command injection. Defenders should prioritize verifying exposure, applying patches, and monitoring for suspicious activity.

  • Verify exposure of Skyeye deployments to unauthenticated OS command injection
  • Assess and apply patches or mitigations to prevent exploitation
  • Monitor for suspicious activity indicating potential exploitation attempts
  • Implement compensating controls such as WAF rules to detect and prevent exploitation

Technical summary

The vulnerability exists in the /post/TtsController/textToSpeech endpoint of Dromara Skyeye, allowing unauthenticated attackers to inject OS commands via the format parameter. This is achieved by injecting a single quote to break out of the PowerShell string, enabling command execution as the Skyeye service account on Windows. Affected product deployments should be verified for exposure, especially those accessible from the internet, and patches or mitigations should be applied as available. The vulnerability has a CVSS score of 9.3 and is considered critical.

Defensive priority

Defenders should prioritize verifying exposure of Skyeye deployments, especially those accessible from the internet, and apply patches or mitigations as available.

Recommended defensive actions

  • Verify exposure of Dromara Skyeye deployments, especially those accessible from the internet
  • Review and apply patches or mitigations as available from the vendor
  • Monitor for suspicious activity on affected systems
  • Implement compensating controls such as WAF rules to detect and prevent exploitation attempts
  • Review asset inventory to identify potentially affected systems
  • Plan and schedule vendor-supported updates or mitigations through normal change control
  • Track exceptions and retest remediated assets to ensure successful patching

Evidence notes

The CVE record and source item provide details on the vulnerability, including its existence in Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321. However, specific details about exploitation, impact, and remediation are limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107780 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107780

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107780 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107780

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Dromara Skyeye Unauthenticated OS Command Injection via textToSpeech format Parameter

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107780.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/dromara/skyeye/issues/29

    Supplemental source - issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://github.com/dromara/skyeye/blob/003549ae5615bd114ba5bb8ddf6a8e8ead97c321/skyeye-promote/skyeye-common/src/main/java/com/skyeye/common/service/impl/TtsServiceImpl.java

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/dromara/skyeye

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/dromara-skyeye-unauthenticated-os-command-injection-via-texttospeech-format-parameter

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.