CVE-2026-22244

OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerability. Version 1.11.4 contains a patch.
Configurations

Configuration 1 (hide)

cpe:2.3:a:open-metadata:openmetadata:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:19

Type Values Removed Values Added
Summary
  • (es) OpenMetadata es una plataforma unificada de metadatos. Las versiones anteriores a la 1.11.4 son vulnerables a la ejecución remota de código a través de Inyección de Plantillas del Lado del Servidor (SSTI) en plantillas de correo electrónico de FreeMarker. Un atacante debe tener privilegios administrativos para explotar la vulnerabilidad. La versión 1.11.4 contiene un parche.

15 Jan 2026, 21:14

Type Values Removed Values Added
References () https://github.com/open-metadata/OpenMetadata/commit/bffe7c45807763f9b682021d4211c478d2a08bb3 - () https://github.com/open-metadata/OpenMetadata/commit/bffe7c45807763f9b682021d4211c478d2a08bb3 - Patch
References () https://github.com/open-metadata/OpenMetadata/security/advisories/GHSA-5f29-2333-h9c7 - () https://github.com/open-metadata/OpenMetadata/security/advisories/GHSA-5f29-2333-h9c7 - Exploit, Vendor Advisory
First Time Open-metadata openmetadata
Open-metadata
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
CPE cpe:2.3:a:open-metadata:openmetadata:*:*:*:*:*:*:*:*
CWE CWE-94

08 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-08 16:16

Updated : 2026-06-17 10:19


NVD link : CVE-2026-22244

Mitre link : CVE-2026-22244

CVE.ORG link : CVE-2026-22244


JSON object : View

Products Affected

open-metadata

  • openmetadata
CWE
CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

CWE-94

Improper Control of Generation of Code ('Code Injection')