CVE-2026-42785

OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can submit malicious script content with an action=Evaluate parameter to execute operating system commands in the context of the OpenKM application server.
Configurations

No configuration.

History

26 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-26 15:16

Updated : 2026-06-17 10:48


NVD link : CVE-2026-42785

Mitre link : CVE-2026-42785

CVE.ORG link : CVE-2026-42785


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')