Remote Code Execution Vulnerability in OpenKM Document Management Software by OpenKM
CVE-2026-42785

8.6HIGH

Key Information:

Vendor

Openkm

Vendor
CVE Published:
26 May 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-42785?

OpenKM version 6.3.12 contains a vulnerability that enables authenticated administrators to execute arbitrary Java or BeanShell code via the /admin/Scripting endpoint. By exploiting this flaw, attackers can submit malicious scripts with the action=Evaluate parameter, which could allow them to run operating system commands within the context of the OpenKM application server. This poses significant risks to systems running the affected software, necessitating prompt action to mitigate potential attacks.

Affected Version(s)

OpenKM Community Edition 0 <= 6.3.12

OpenKM Professional Edition 0 <= 7.1.47

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Terra System Labs Pvt. Ltd.
.