Command Injection Vulnerability in OpenHarness by HKUDS
CVE-2026-40502

8.7HIGH

Key Information:

Vendor

Hkuds

Vendor
CVE Published:
16 April 2026

What is CVE-2026-40502?

An identified command injection vulnerability in OpenHarness prior to commit dd1d235 enables remote gateway users with chat access to execute sensitive administrative commands. This occurs due to inadequate differentiation between local-only commands and those deemed safe for remote execution within the gateway handler. Attackers can exploit this flaw to alter permissions and execute commands such as /permissions full_auto, enabling them to manipulate the OpenHarness instance without appropriate authorization from a system operator.

Affected Version(s)

OpenHarness 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chia Min Jun Lennon
.