CVE-2026-40502

OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between local-only and remote-safe commands in the gateway handler. Attackers can execute administrative commands such as /permissions full_auto through remote chat sessions to change permission modes of a running OpenHarness instance without operator authorization.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hkuds:openharness:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-16 01:16

Updated : 2026-07-14 21:16


NVD link : CVE-2026-40502

Mitre link : CVE-2026-40502

CVE.ORG link : CVE-2026-40502


JSON object : View

Products Affected

hkuds

  • openharness
CWE
CWE-862

Missing Authorization