CVE-2026-60102Disclosure

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellCommand() method fails to sanitize command substitution sequences, allowing authenticated attackers to inject arbitrary shell commands through user-controlled filenames. Attackers can supply malicious filenames containing unescaped command substitution payloads through operations such as file upload, folder creation, rename, or deletion, which are interpolated into a double-quoted shell context and executed via proc_open() through /bin/sh -c before smbclient runs, resulting in arbitrary command execution on the underlying system.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 6 mentions (2026-07-08); latest day: 1
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-07-08: 6Mentions · 2026-07-09: 1Mentions · 2026-07-11: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-11: 1Technical Details · 2026-07-08: 3Technical Details · 2026-07-09: 1Technical Details · 2026-07-11: 107-0807-0907-11
Signal classification3 categories
Disclosure
337.5%
General
337.5%
Patch
225.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-086
Disclosure3General3
2026-07-091
Patch1
2026-07-111
Patch1
Full discourse8 posts
  • hacker.house@hackerfantastic
    General

    Horde Framework, CVE-2026-60102.

    Post summary

    The text merely names the CVE (CVE-2026-60102) associated with Horde Framework without providing any additional details or context.

    1111123.3K
    106.7K followersView on X
  • hacker.house@myhackerhouse
    Disclosure

    Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver (CVE-2026-60102) https://nvd.nist.gov/vuln/detail/CVE-2026-60102 - learn more (https://hacker.house/blog/inference-fuzzing-with-recursive-prompting-a-practical-methodology-for-llm-driven-code-audits)

    Post summary

    The post announces an OS command injection vulnerability (CVE-2026-60102) affecting Horde VFS API versions prior to 3.0.1, providing an NVD link but no evidence of exploits, active use, or available fixes.

    040722.6K
    20.6K followersView on X
  • YogSotho@YogSoth0
    General

    @hackerfantastic https://nvd.nist.gov/vuln/detail/CVE-2026-60102

    Post summary

    The tweet simply forwards a link to the NVD page for CVE‑2026‑60102, providing no additional context or details.

    10020134
    1.9K followersView on X
  • YogSotho@YogSoth0
    General

    https://nvd.nist.gov/vuln/detail/CVE-2026-60102 #0days #Horde #CVE #cybernews #cybersecurity #security #exploit #infosec

    Post summary

    The tweet only provides a link to the NVD entry for CVE‑2026 ră85 and hashtags; no additional technical or exploit information is supplied.

    01010816
    1.6K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-60102 (CVSS 8.8) Horde VFS API <3[.]0[.]1 - OS command injection in Horde_Vfs_Smb driver. Authenticated attackers can execute arbitrary commands via malicious filenames. Patch immediately to 3[.]0[.]1+ #CVE #Vulnerability #PatchNow https://t.co/2C3jtUMMsS

    Post summary

    The content announces CVE-2026-60102, an authenticated OS command injection exploit in Horde VFS API, and urges immediate patching to version 3.0.1+.

    0000044
    71 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - OS command injection in Horde VFS SMB driver (CVE-2026-60102) Horde Virtual File System (VFS) API is vulnerable to OS command injection in the Horde_Vfs_Smb driver used to interact with SMB shares via smbclient. The root cause is improper input sanitization in _escapeShellCommand(), which fails to neutralize command substitution sequences, enabling shell metacharacters to survive escaping. An authenticated attacker can exploit this by supplying a crafted filename during upload, folder creation, rename, or delete operations, which gets passed to /bin/sh -c before smbclient executes. Successful exploitation results in arbitrary command execution on the server under the web/app service account, potentially enabling data theft, lateral movement, or full service compromise. 👉 Affected: horde/vfs < 3.0.1 | Upgrade to 3.0.1

    Post summary

    CVE-2026-60102 is a high‑severity OS command‑injection flaw in Horde VFS SMB driver that lets authenticated users execute arbitrary commands; the issue is mitigated by upgrading to version 3.0.1.

    00000160
    246 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-60102 Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellCommand() method fai… https://www.cve.org/CVERecord?id=CVE-2026-60102 ----- Traducción: CVE-2026-60102 Hor… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑60102, describing an OS command injection flaw in Horde VFS API and linking to the official CVE record, without mentioning patches, exploitation, or PoC details.

    0000044
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-60102 Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellCommand() method fai… https://www.cve.org/CVERecord?id=CVE-2026-60102

    Post summary

    The CVE-2026-60102 entry describes an OS command injection flaw in the Horde Virtual File System (VFS) before 3.0.1, noting a failure in the _escapeShellCommand() method, but does not provide PoC, exploit tools, or patch details.

    00000765
    57.8K followersView on X

Explore more