Skip to content
Vulnerabilities

Skyeye TTS Vulnerability Enables Unauth PowerShell Execution on Windows Servers

A critical unauthenticated command injection in Dromara Skyeye allows remote attackers to execute PowerShell code on Windows servers via a text-to-speech endpoint.

Skyeye TTS Vulnerability Enables Unauth PowerShell Execution on Windows Servers
Illustration: Malware Brief

Key points

  • CVE-2026-107780 is rated 9.3 CRITICAL by the NVD.
  • The flaw exists in the /post/TtsController/textToSpeech endpoint.
  • Attackers can execute commands as the Skyeye service account.

Organisations running Dromara Skyeye face immediate risk from a critical remote code execution vulnerability that requires no authentication. The flaw, tracked as CVE-2026-107780, allows attackers to inject operating system commands through a specific parameter in the application’s text-to-speech functionality. According to the National Vulnerability Database, the issue is rated 9.3, placing it in the critical severity range.

The vulnerability stems from improper input validation in the unauthenticated /post/TtsController/textToSpeech endpoint. By manipulating the ‘format’ parameter, an attacker can break out of the existing PowerShell string context. This enables the execution of arbitrary commands on the underlying Windows system. The commands run with the privileges of the Skyeye service account, potentially granting attackers significant control over the host environment.

How it unfolded

  • The vulnerability was identified in Dromara Skyeye versions up to commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321.
  • Security researchers determined that injecting a single quote into the format parameter breaks the PowerShell string boundary.
  • The National Vulnerability Database assigned CVE-2026-107780 and classified the weakness under CWE-78, indicating OS command injection.

Who is affected

Any organisation or individual using Dromara Skyeye on Windows systems is affected. The vulnerability applies to all versions of the software up to and including the commit identified above. Because the endpoint is unauthenticated, the flaw is exposed to the internet if the service is publicly accessible. Attackers do not need valid credentials to exploit this issue, making it a high-value target for automated scanning and initial access attempts.

The fix

No patch or update has been confirmed yet. The vulnerability persists in all versions of Dromara Skyeye prior to the specified commit. Users should monitor vendor communications for an official remediation. Until a fix is available, organisations must rely on network-level controls to mitigate the risk.

What to do and how to stay safe: Dromara Skyeye

  • Review firewall rules to block external access to the /post/TtsController/textToSpeech endpoint if it is not required for public users.
  • Monitor Windows event logs and PowerShell execution logs for unusual command activity originating from the Skyeye service account.
  • Restrict network access to the Skyeye application to trusted internal subnets only, if external access is not strictly necessary.
  • Verify that no other unauthenticated endpoints are exposed to the internet, as this flaw indicates a broader exposure risk.

Step-by-step guide: Patch Management: Eight Questions Answered for Stability

General security guidance from the Malware Brief newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What is CVE-2026-107780?

It is a critical OS command injection vulnerability in Dromara Skyeye that allows unauthenticated attackers to execute PowerShell commands on Windows.

How severe is this vulnerability?

The National Vulnerability Database rates it 9.3, which is considered critical severity.

Do attackers need a password to exploit this?

No, the endpoint is unauthenticated, meaning no login credentials are required to trigger the exploit.

Sources

  1. CVE Program
  2. NVD
Dromara SkyeyeCVE-2026-107780OS command injectionWindowsNVD

Related stories

Cybersecurity news without the noiseDaily Briefing