The Debian Security Team has published DSA-6544-1, addressing multiple vulnerabilities in the web interface of SABnzbd+, the widely deployed open-source binary newsreader. The flaws can be chained or individually abused to achieve arbitrary code execution on the host running the service, or to bypass authentication/authorization controls protecting the web UI. For the stable distribution (Debian 13 "trixie"), the issue is resolved in version 4.5.0+dfsg-1+deb13u2. The original advisory is available at the Debian/LinuxSecurity advisory page.
This is not a theoretical exposure. SABnzbd+ is frequently installed on home-lab media servers, NAS appliances, seedboxes, and — critically — on infrastructure that administrators expose to the internet for remote queue management. A web UI that hands an attacker code execution on the underlying host is a beachhead: the service typically runs with read/write access to large storage volumes, holds Usenet and indexer credentials in plaintext configuration, and is commonly co-located with other automation tooling (Sonarr, Radarr, download clients) that expands lateral movement options. If you run SABnzbd+ anywhere in your environment — corporate or otherwise — treat this as a patch-now event.
Technical Analysis
Affected Products and Versions
- Product: SABnzbd+ (
sabnzbdpluspackage) - Affected component: Embedded web UI (the CherryPy-based interface, default TCP port 8080, and the HTTPS interface on 9090 when configured)
- Affected distribution: Debian 13 "trixie" (stable); older Debian releases and derivatives shipping unpatched SABnzbd+ builds should be assumed vulnerable until confirmed otherwise
- Fixed version:
4.5.0+dfsg-1+deb13u2for trixie
Debian has not assigned CVE identifiers in the public summary of DSA-6544-1 at the time of this writing; the advisory describes multiple vulnerabilities in the web UI resulting in arbitrary code execution or authorization bypass. Defenders should monitor the Debian security tracker for CVE assignments as they are published.
How the Vulnerabilities Work — Defender's Perspective
Two distinct impact classes are described:
-
Authorization bypass. The web UI enforces access via an API key and/or username-password authentication. An authorization bypass means an unauthenticated remote attacker can reach privileged API endpoints — queue manipulation, configuration changes, file operations — without valid credentials. In practice, this class of bug in SABnzbd-class applications usually stems from missing or inconsistent authorization decorators on API routes, path normalization issues, or endpoints that trust client-supplied parameters to identify the requesting user.
-
Arbitrary code execution. SABnzbd+ exposes powerful functionality through its web UI by design: configurable post-processing scripts, category-specific script execution, and user-controlled paths. A code execution flaw here typically means an attacker can abuse one of these mechanisms — or a secondary injection flaw in a UI-handled parameter — to run operating system commands in the context of the
sabnzbdplusservice account.
The realistic attack chain is: attacker reaches the exposed web UI (port 8080) → bypasses authentication → invokes a code-execution-capable endpoint → achieves command execution as the service user → establishes persistence, reads sabnzbd.ini for stored credentials, and pivots.
Exploitation Requirements
- Network reachability to the web UI. If SABnzbd+ is bound to
localhostor sits behind an authenticated reverse proxy with proper ACLs, exposure is substantially reduced. If it listens on0.0.0.0:8080— a common default for containerized and NAS deployments — it is directly exploitable by any host that can route to it. - No valid credentials required if the authorization bypass is used.
Exploitation Status
At publication, there is no confirmed public proof-of-concept and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog. However, SABnzbd+ instances are trivially discoverable via internet scanning (the login page and API endpoints have distinctive fingerprints), and the window between a Debian DSA and opportunistic scanning is routinely measured in hours. Treat internet-exposed instances as potentially already probed and review logs accordingly.
Detection & Response
The highest-fidelity detection strategy has three layers: (1) the SABnzbd+ process spawning unexpected child processes, (2) unexpected network exposure/connections to the web UI ports, and (3) forensic review of the host for post-exploitation artifacts.
Sigma Rules
---
title: SABnzbd+ Spawning Shell or Interpreter Child Process
id: 3f8a2c41-9b7e-4d15-a6c2-8e1f5b9d3a07
status: experimental
description: Detects the SABnzbd+ service process spawning shells, interpreters, or download tooling, consistent with post-exploitation command execution via the web UI code execution flaw (Debian DSA-6544-1).
references:
- https://linuxsecurity.com/advisories/debian/debian-dsa-6544-1-sabnzbdplus
- https://attack.mitre.org/techniques/T1059/004/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.execution
- attack.t1059.004
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- '/SABnzbd.py'
- '/sabnzbdplus'
- '/python3'
selection_parent_cmd:
ParentCommandLine|contains:
- 'SABnzbd.py'
- 'sabnzbdplus'
selection_child:
Image|endswith:
- '/bash'
- '/sh'
- '/dash'
- '/zsh'
- '/curl'
- '/wget'
- '/nc'
- '/ncat'
- '/socat'
- '/base64'
- '/chmod'
- '/chown'
- '/useradd'
- '/crontab'
condition: selection_parent and selection_parent_cmd and selection_child
falsepositives:
- Legitimate administrator-configured post-processing scripts invoking shells; review script paths under the SABnzbd scripts directory to baseline
level: high
---
title: SABnzbd.exe Spawning Command Interpreter on Windows
id: 6c1d9e72-4a3b-4f08-b2d5-7c9e1a4f6b23
status: experimental
description: Detects the SABnzbd+ Windows process spawning command interpreters or scripting engines, consistent with command execution via the web UI (Debian DSA-6544-1 class of flaw applies cross-platform).
references:
- https://linuxsecurity.com/advisories/debian/debian-dsa-6544-1-sabnzbdplus
- https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.execution
- attack.t1059.003
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\SABnzbd.exe'
- '\SABnzbd-service.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
condition: selection_parent and selection_child
falsepositives:
- Post-processing scripts legitimately invoked by SABnzbd categories; baseline known script names and paths
level: high
---
title: External Network Connection to SABnzbd+ Web UI Port
id: 9e4b7d15-2f6a-4c81-8a3d-1b5e7c9f2a48
status: experimental
description: Detects inbound network connections to the default SABnzbd+ web UI ports from non-loopback sources, identifying unintended exposure of the management interface relevant to DSA-6544-1 exploitation.
references:
- https://linuxsecurity.com/advisories/debian/debian-dsa-6544-1-sabnzbdplus
- https://attack.mitre.org/techniques/T1190/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.initial_access
- attack.t1190
logsource:
category: network_connection
product: linux
detection:
selection_port:
DestinationPort:
- 8080
- 9090
selection_process:
Image|endswith:
- '/python3'
- '/sabnzbdplus'
filter_loopback:
DestinationIp|startswith:
- '127.'
- '::1'
condition: selection_port and selection_process and not filter_loopback
falsepositives:
- Legitimate remote administration from trusted LAN hosts; restrict by allowlisting known management subnets in a tuning filter
level: medium
KQL — Microsoft Sentinel / Defender
The first query hunts process execution telemetry from SABnzbd hosts ingested via the Defender for Endpoint Linux agent. The second hunts Syslog (via the AMA agent) for evidence of the service accepting external connections or suspicious shell execution attributed to the service account.
// Hunt 1: SABnzbd+ spawning suspicious child processes (MDE Linux/Windows)
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName has_any ("SABnzbd", "sabnzbdplus")
or InitiatingProcessCommandLine has_any ("SABnzbd.py", "sabnzbdplus")
| where FileName in~ ("bash", "sh", "dash", "zsh", "curl", "wget", "nc", "ncat", "socat", "base64", "cmd.exe", "powershell.exe", "pwsh.exe")
| project TimeGenerated, DeviceName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, AccountName, InitiatingProcessRemoteSessionIP
| order by TimeGenerated desc;
// Hunt 2: Syslog - shell activity under the sabnzbd service account and auth events on the host
Syslog
| where TimeGenerated > ago(14d)
| where SyslogMessage has_any ("sabnzbd", "SABnzbd")
and (SyslogMessage has_any ("/bin/sh", "/bin/bash", "curl", "wget", "nc -", "base64 -d", "chmod +x")
or SyslogMessage has_any ("authentication failure", "session opened"))
| project TimeGenerated, Computer, ProcessName, SyslogMessage
| order by TimeGenerated desc;
// Hunt 3: Network exposure check - devices listening or accepting connections on SABnzbd ports
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where LocalPort in (8080, 9090)
and (InitiatingProcessFileName has_any ("SABnzbd", "python") or FileName has_any ("SABnzbd", "python"))
| where RemoteIP !startswith "127." and RemoteIP != "::1"
| summarize ConnectionCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by DeviceName, RemoteIP, RemotePort, LocalPort
| order by ConnectionCount desc
Velociraptor VQL
Use this artifact to sweep your Linux fleet for SABnzbd+ processes, their listening sockets, and any shell descendants — a fast triage for both exposure and active compromise.
-- Triage SABnzbd+ hosts: identify the service, its listeners, and suspicious child processes
LET procs = SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)sabnzbd'
LET listeners = SELECT Lfd, Pid, Name, LocalAddress, LocalPort, RemoteAddress, RemotePort, Status
FROM netstat()
WHERE LocalPort IN (8080, 9090) AND Status = 'LISTEN'
SELECT 'service_process' AS Finding, Pid, Ppid, Name, CommandLine, Username,
NULL AS LocalAddress, NULL AS LocalPort, NULL AS Status
FROM procs
UNION ALL
SELECT 'listening_socket' AS Finding, Pid, NULL AS Ppid, Name, NULL AS CommandLine, NULL AS Username,
LocalAddress, LocalPort, Status
FROM listeners
UNION ALL
SELECT 'suspicious_child' AS Finding, Pid, Ppid, Name, CommandLine, Username,
NULL AS LocalAddress, NULL AS LocalPort, NULL AS Status
FROM pslist()
WHERE Ppid IN (SELECT Pid FROM procs)
AND Name =~ '(?i)^(bash|sh|dash|zsh|curl|wget|nc|ncat|socat|base64)$'
Remediation and Verification Script
The following Bash script patches the package on Debian trixie, verifies the installed version, checks for dangerous exposure (web UI bound to all interfaces without authentication), and applies baseline hardening. Run it with root privileges on each SABnzbd+ host.
#!/usr/bin/env bash
# DSA-6544-1 remediation: patch, verify, and harden SABnzbd+ on Debian 13 (trixie)
set -euo pipefail
FIXED_VERSION="4.5.0+dfsg-1+deb13u2"
echo "[*] Updating package index and upgrading sabnzbdplus..."
apt-get update -qq
apt-get install -y --only-upgrade sabnzbdplus
echo "[*] Verifying installed version..."
INSTALLED=$(dpkg-query -W -f='${Version}' sabnzbdplus 2>/dev/null || echo "not-installed")
echo " Installed: ${INSTALLED}"
if [ "$INSTALLED" = "not-installed" ]; then
echo "[!] sabnzbdplus is not installed on this host. Nothing further to do."
exit 0
fi
if dpkg --compare-versions "$INSTALLED" lt "$FIXED_VERSION"; then
echo "[FAIL] Installed version ${INSTALLED} is OLDER than fixed ${FIXED_VERSION}. Investigate mirror/pin configuration."
exit 1
fi
echo "[OK] Version ${INSTALLED} meets or exceeds the fixed release."
echo "[*] Restarting service to load patched code..."
systemctl restart sabnzbdplus 2>/dev/null || systemctl --user restart sabnzbd 2>/dev/null || echo "[!] Restart manually if not managed by systemd."
echo "[*] Checking web UI bind address exposure..."
for PID in $(pgrep -f -i sabnzbd || true); do
ss -lntp 2>/dev/null | grep -E ':(8080|9090)' | grep -E '0\.0\.0\.0|::' && \
echo "[WARN] SABnzbd web UI is listening on ALL interfaces. Restrict exposure (see hardening steps below)."
done
CONFIG=$(find /etc /home /var/lib -maxdepth 4 -name 'sabnzbd.ini' 2>/dev/null | head -n 1 || true)
if [ -n "$CONFIG" ]; then
echo "[*] Found config: ${CONFIG}"
grep -qE '^host\s*=\s*(127\.0\.0\.1|localhost)' "$CONFIG" \
&& echo "[OK] Web UI bound to loopback." \
|| echo "[WARN] 'host' is not loopback in ${CONFIG}. Set host = 127.0.0.1 unless remote access is strictly required."
grep -qE '^username\s*=\s*\S+' "$CONFIG" \
&& echo "[OK] Web UI authentication appears configured." \
|| echo "[WARN] No web UI username set. Enable authentication immediately (Config > General)."
else
echo "[!] sabnzbd.ini not found in standard locations; review bind/auth settings manually."
fi
echo "[*] Applying firewall restriction for ports 8080/9090 (loopback + RFC1918 only)..."
if command -v ufw >/dev/null 2>&1; then
ufw deny 8080/tcp >/dev/null 2>&1 || true
ufw deny 9090/tcp >/dev/null 2>&1 || true
echo "[OK] UFW deny rules added for 8080/9090. Add explicit allows for trusted management subnets."
else
echo "[!] UFW not present; apply equivalent nftables/iptables rules manually."
fi
echo "[*] Remediation complete. Re-run version check after any future package operations."
Remediation
-
Patch immediately. Upgrade
sabnzbdpluson all Debian 13 (trixie) systems to 4.5.0+dfsg-1+deb13u2 or later:apt-get update && apt-get install --only-upgrade sabnzbdplus. Restart the service afterward — a patched package with a running unpatched process is still unpatched. Official reference: DSA-6544-1 advisory and the Debian Security Tracker. -
Inventory and isolate exposed instances. Scan your network and cloud assets for listeners on TCP 8080/9090 running SABnzbd+. Any instance reachable from the internet should be treated as potentially compromised — pull logs, review
sabnzbd.inifor unexpected script/path changes, and check for unexpected child processes or outbound connections from the service account before simply patching. -
Reduce the attack surface. Bind the web UI to
127.0.0.1(host = 127.0.0.1insabnzbd.ini) and front remote access with an authenticated reverse proxy (with its own TLS and auth), or restrict access via firewall rules to known management subnets. Do not rely on SABnzbd's own authentication as the sole control given the authorization-bypass component of this DSA. -
Enforce strong web UI authentication. Set a unique username/password and rotate the API key. Assume any API key stored on a previously internet-exposed instance is compromised and rotate credentials for connected indexers and Usenet providers as well.
-
Constrain the service account. Ensure SABnzbd+ runs as a dedicated, unprivileged user with no sudo rights, no shell, and filesystem access limited to its download directories. This meaningfully blunts the arbitrary-code-execution impact even if a future flaw lands.
-
Monitor downstream/derivative distributions. Ubuntu, Mint, and container images bundling SABnzbd+ may lag the Debian fix. If you deploy SABnzbd+ via Docker or pip rather than the distro package, confirm you are running the patched upstream release and not a stale image tag.
-
Hunt before you close the ticket. Because the flaws were publicly disclosed, retroactively review web UI access logs (if fronted by a proxy), Syslog, and process telemetry for the 14–30 days preceding the patch for the indicators covered in the detection section above.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.