Command Injection Vulnerability in OpenHarness by HKUDS
CVE-2026-40502
8.7HIGH
What is CVE-2026-40502?
An identified command injection vulnerability in OpenHarness prior to commit dd1d235 enables remote gateway users with chat access to execute sensitive administrative commands. This occurs due to inadequate differentiation between local-only commands and those deemed safe for remote execution within the gateway handler. Attackers can exploit this flaw to alter permissions and execute commands such as /permissions full_auto, enabling them to manipulate the OpenHarness instance without appropriate authorization from a system operator.
Affected Version(s)
OpenHarness 0
