Remote Code Execution Vulnerability in OpenKM Document Management Software by OpenKM
CVE-2026-42785
Key Information:
- Vendor
Openkm
- Vendor
- CVE Published:
- 26 May 2026
Badges
What is CVE-2026-42785?
OpenKM version 6.3.12 contains a vulnerability that enables authenticated administrators to execute arbitrary Java or BeanShell code via the /admin/Scripting endpoint. By exploiting this flaw, attackers can submit malicious scripts with the action=Evaluate parameter, which could allow them to run operating system commands within the context of the OpenKM application server. This poses significant risks to systems running the affected software, necessitating prompt action to mitigate potential attacks.
Affected Version(s)
OpenKM Community Edition 0 <= 6.3.12
OpenKM Professional Edition 0 <= 7.1.47
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
