External risk intelligence

Dromara Skyeye Unauthenticated OS Command Injection in TextToSpeech Endpoint

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-107780

The vulnerability exists in an unauthenticated web endpoint (/post/TtsController/textToSpeech) within the application. Web applications and their APIs are commonly deployed as internet-facing services, making this endpoint a likely candidate for public exposure in many real-world deployments.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in Dromara Skyeye, specifically in an endpoint that converts text to speech. Attackers can exploit this flaw to execute commands on the system, potentially leading to unauthorized access and control. The main concern at this stage is to confirm if this technology is in use and, if so, to what extent it is exposed.

  • Unauthenticated access allows command execution.
  • Remotely executable code impacts system integrity.
  • Confirm relevance and exposure for your environment.

Attack Path

How an attacker could exploit the issue

An attacker can reach the vulnerability by sending a request to an exposed web endpoint. This endpoint is designed to convert text to speech and is accessible without authentication. The attacker can manipulate a parameter within this request to inject malicious commands, which are then executed on the server's operating system.

  • Unauthenticated network access required.
  • Malicious input in `format` parameter.
  • Execute arbitrary commands as service account.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary commands on the server when the `/post/TtsController/textToSpeech` endpoint is accessible. This could occur when the application processes specially crafted requests to the `format` parameter, leading to the execution of commands with the privileges of the Skyeye service account on Windows systems.

  • Server commands could be executed.
  • Via unauthenticated network requests.
  • Compromise of the Skyeye service account.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Dromara Skyeye application's unauthenticated text-to-speech endpoint is vulnerable to OS command injection, allowing unauthenticated attackers to execute commands as the Skyeye service account on Windows systems. Identifying all instances of Skyeye, confirming their accessibility and business criticality, and then assigning ownership for remediation planning is the primary initial step.

  • App or platform teams likely own this.
  • Verify Skyeye instances and network exposure.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Dromara Skyeye?

Dromara Skyeye is a software platform designed to manage and automate various enterprise-level business operations. It acts as a centralized management suite, and this vulnerability specifically affects its integrated text-to-speech module, which provides audio output capabilities for automated systems.

What does OS command injection mean for CVE-2026-107780?

This vulnerability is classified as CWE-78, or OS Command Injection. It occurs when an application passes unsafe user input directly to a system shell. In this case, the software fails to sanitize data in the text-to-speech parameter, allowing an attacker to escape the intended string and run unauthorized commands directly on the underlying Windows operating system.

How is this vulnerability triggered?

An attacker triggers this flaw by sending a network request to the unauthenticated /post/TtsController/textToSpeech endpoint. By injecting a single quote into the 'format' parameter, they can manipulate the command being processed. Requests that do not include this specific malicious formatting or are directed to other parts of the application will not trigger this particular command execution path.

Is my instance at risk?

Halo Surface Signal indicates that this endpoint is likely internet-facing in many deployments because it is a web-based service. If your Skyeye instance is accessible from the internet without restricted access controls, it faces a higher probability of being targeted compared to instances strictly limited to internal, private networks.

What should I do first to address this?

Your first step is to perform an inventory of all Dromara Skyeye instances running in your environment. Once identified, evaluate their network exposure to determine if they are reachable by unauthorized users. Coordinate with the teams managing these servers to prioritize remediation planning, focusing on instances that are currently exposed to broader network access.

References