CVE-2026-40502: OpenHarness Remote Administrative Command Injection via Gateway Handler
OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between local-only and remote-safe commands in the gateway handler. Attackers can execute administrative commands such as /permissions fullauto through remote chat sessions to change permission modes of a running OpenHarness instance without operator authorization.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40502?
CVE-2026-40502 is rated as a high severity vulnerability due to its capability to allow remote command injection.
How do I fix CVE-2026-40502?
To fix CVE-2026-40502, upgrade OpenHarness to the version after commit dd1d235 to patch the vulnerability.
What does CVE-2026-40502 affect?
CVE-2026-40502 affects OpenHarness prior to commit dd1d235, specifically impacting remote users with chat access.
Can CVE-2026-40502 be exploited remotely?
Yes, CVE-2026-40502 can be exploited remotely by users with chat access to execute sensitive administrative commands.
What actions can attackers take exploiting CVE-2026-40502?
Attackers exploiting CVE-2026-40502 can execute arbitrary administrative commands on the OpenHarness system.