Executive brief
NewSoftOA, an office automation and enterprise resource planning platform, contains a critical security flaw. This vulnerability allows an unauthorized person to run arbitrary commands on the server hosting the software. An attacker could use this to take full control of the system, access sensitive corporate data, or disrupt business operations.
Technical details
NewSoftOA versions prior to 10.1.8.3 are vulnerable to OS Command Injection (CWE-78). The flaw exists due to improper neutralization of special elements used in an OS command, allowing an unauthenticated attacker to execute arbitrary system-level commands. While some descriptions mention 'local' attackers, the CVSS vector (AV:N) and the nature of the OA platform indicate the vulnerability is reachable over the network. Successful exploitation grants the attacker full remote code execution (RCE) capabilities on the underlying server. Users are advised to update to version 10.1.8.3 or later to remediate the issue.
Affected products
- NewSoft NewSoftOA before 10.1.8.3
Timeline
- 2026-04-21: disclosed
- 2026-04-21: advisory
- 2026-04-21: patched: Update to version 10.1.8.3 or later.