PatchSiren

Spotweb CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Spotweb CVE published 2026-10-10

CVE-2026-108546

CVE-2026-108546 is an OS command injection vulnerability in Spotweb's runcommand NZB handler. Attackers can publish spots with malicious titles to execute commands as the Spotweb PHP process when a user downloads the spot. This vulnerability allows for potential command execution as the Spotweb PHP process, possible lateral movement within the network, and requires verification of Spotweb versions and con [truncated]