Junglewise Threat Intelligence

CVE-2026-65711: nuxsmin sysPass OS command injection in FileBackupService

CVE-2026-65711 · Severity: high · CVSS 7.2 · Published 2026-07-24

Technologies: Nuxsmin Syspass.

Executive brief

sysPass is an open-source password manager used by organizations to store and manage sensitive credentials. A security flaw allows an administrator to inject malicious commands into the system's backup configuration. If exploited, an attacker could gain full control over the server, potentially exposing all stored passwords and encryption keys.

Technical details

An OS command injection vulnerability exists in the FileBackupService::doBackupFiles() function of sysPass through version 3.2.11. The application constructs a 'tar' shell command using string concatenation with the 'siteBackupPath' configuration value without proper sanitization or escaping via escapeshellarg(). An authenticated user with administrative privileges can modify this path to include shell metacharacters (e.g., semicolons or backticks) to execute arbitrary commands as the web server user (e.g., www-data). Because the project is reportedly abandoned, no official patch is available; users are advised to manually apply escapeshellarg() to the affected code or migrate to a supported password manager.

Affected products

  • nuxsmin sysPass through 3.2.11

Timeline

  • 2026-07-11: disclosed: Vulnerability discovered and reported to VulnCheck
  • 2026-07-23: advisory: Public disclosure due to project abandonment
  • 2026-07-24: other: CVE record published

References