PatchSiren cyber security CVE debrief
CVE-2026-60102 horde CVE debrief
CVE-2026-60102 is an OS command injection vulnerability in the Horde_Vfs_Smb driver of Horde Virtual File System (VFS) API before version 3.0.1. The vulnerability occurs because the _escapeShellCommand() method fails to sanitize command substitution sequences. This allows authenticated attackers to inject arbitrary shell commands through user-controlled filenames. The commands are executed via proc_open() through /bin/sh -c before smbclient runs, resulting in arbitrary command execution on the underlying system.
- Vendor
- horde
- Product
- Vfs
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-08
- Original CVE updated
- 2026-07-10
- Advisory published
- 2026-07-08
- Advisory updated
- 2026-07-10
Who should care
Administrators and users of Horde Virtual File System (VFS) API versions before 3.0.1 should be aware of this vulnerability. As the vulnerability requires authentication, users with access to the VFS API are at risk.
Technical summary
The Horde Virtual File System (VFS) API before version 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver. The _escapeShellCommand() method fails to properly sanitize command substitution sequences in user-controlled filenames. Attackers can inject arbitrary shell commands through operations like file upload, folder creation, rename, or deletion. These commands are executed via proc_open() in a double-quoted shell context, leading to arbitrary command execution on the underlying system.
Defensive priority
High
Recommended defensive actions
- Update Horde Virtual File System (VFS) API to version 3.0.1 or later
- Restrict access to the VFS API to only necessary users
- Monitor VFS API logs for suspicious activity
- Implement additional security measures such as Web Application Firewalls (WAFs) to detect and prevent exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-08T17:17:28.997Z and was last modified on 2026-07-10T18:46:32.250Z. The NVD entry is currently Deferred. Evidence is limited to public sources and may not reflect the full scope of affected systems or available mitigations. Defenders should verify the vulnerability's impact on their specific environments and review official advisories for detailed guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-60102 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-60102
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-60102 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60102
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/horde/Vfs/commit/41f74b4acfc144e09013d04dd121e0a5da808361
-
Source reference
Unverified legacy reference
URL: https://github.com/horde/Vfs/pull/10
-
Source reference
Unverified legacy reference
URL: https://github.com/horde/Vfs/releases/tag/v3.0.1
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/horde-vfs-os-command-injection-via-horde-vfs-smb-driver
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.