Improper Access Control Vulnerability in OpenHarness File Tools
CVE-2026-22682

8.4HIGH

Key Information:

Vendor

Hkuds

Vendor
CVE Published:
7 April 2026

What is CVE-2026-22682?

OpenHarness versions prior to a specific commit are vulnerable due to an improper access control flaw in its built-in file tools. This vulnerability arises from inconsistent parameter handling during permission enforcement, which allows attackers who can influence agent tool execution to read sensitive local files beyond the intended repository scope. Malicious actors exploiting this flaw can bypass established deny rules by manipulating the path parameter, gaining unauthorized access to critical files such as configuration files, credentials, and SSH keys. The attackers are also able to create and overwrite files in restricted host directories when operating in full_auto mode, posing a significant security concern.

Affected Version(s)

OpenHarness 0 < 166fcfefb7614dbac51bd061f56542725b0298e9

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chia Min Jun Lennon
.