CVE-2026-6819

HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /reload-plugins to remote senders by default. Attackers who gain access through the channel layer can remotely manage plugin trust and activation state, enabling unauthorized plugin installation and activation on the system.
Configurations

No configuration.

History

22 Apr 2026, 14:17

Type Values Removed Values Added
References () https://github.com/HKUDS/OpenHarness/pull/156 - () https://github.com/HKUDS/OpenHarness/pull/156 -

21 Apr 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-21 20:17

Updated : 2026-04-22 21:24


NVD link : CVE-2026-6819

Mitre link : CVE-2026-6819

CVE.ORG link : CVE-2026-6819


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions