CVE-2026-40502

OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between local-only and remote-safe commands in the gateway handler. Attackers can execute administrative commands such as /permissions full_auto through remote chat sessions to change permission modes of a running OpenHarness instance without operator authorization.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hkuds:openharness:*:*:*:*:*:*:*:*

History

23 Apr 2026, 19:48

Type Values Removed Values Added
References () https://github.com/HKUDS/OpenHarness/commit/dd1d235450dd987b20bff01b7bfb02fe8620a0af - () https://github.com/HKUDS/OpenHarness/commit/dd1d235450dd987b20bff01b7bfb02fe8620a0af - Patch
References () https://github.com/HKUDS/OpenHarness/pull/127 - () https://github.com/HKUDS/OpenHarness/pull/127 - Exploit, Issue Tracking
References () https://www.vulncheck.com/advisories/openharness-remote-administrative-command-injection-via-gateway-handler - () https://www.vulncheck.com/advisories/openharness-remote-administrative-command-injection-via-gateway-handler - Third Party Advisory
CPE cpe:2.3:a:hkuds:openharness:*:*:*:*:*:*:*:*
First Time Hkuds openharness
Hkuds

16 Apr 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-16 01:16

Updated : 2026-04-23 19:48


NVD link : CVE-2026-40502

Mitre link : CVE-2026-40502

CVE.ORG link : CVE-2026-40502


JSON object : View

Products Affected

hkuds

  • openharness
CWE
CWE-862

Missing Authorization