CVE-2026-105486
OSSRS srs System API api.go systemAPI.Run missing authentication
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 8.0-d0 mitigates this issue. The patch is named bb5fde228f4ca5bd26d96368b61f6e0c21df51df. The affected component should be upgraded.
| CWE | CWE-306 CWE-287 |
| Vendor | ossrs |
| Product | srs |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for ossrs srs
Be the first to know when new high vulnerabilities affecting ossrs srs are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
OSSRS / srs
7.0-a1
References
vuldb.com: https://vuldb.com/vuln/413620 vuldb.com: https://vuldb.com/vuln/413620/cti vuldb.com: https://vuldb.com/cve/CVE-2026-105486 vuldb.com: https://vuldb.com/submit/986193 github.com: https://github.com/ossrs/srs/issues/4690 github.com: https://github.com/ossrs/srs/pull/4726 github.com: https://github.com/ossrs/srs/commit/bb5fde228f4ca5bd26d96368b61f6e0c21df51df github.com: https://github.com/ossrs/srs/releases/tag/v8.0-d0 github.com: https://github.com/ossrs/srs/
Credits
๐ geochen (VulDB User)