CVE-2026-40502: OpenHarness Remote Administrative Command Injection via Gateway Handler

Published Apr 16, 2026
·
Updated

OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between local-only and remote-safe commands in the gateway handler. Attackers can execute administrative commands such as /permissions fullauto through remote chat sessions to change permission modes of a running OpenHarness instance without operator authorization.

Affected Software

2 affected components
OpenHarness OpenHarness<dd1d235
HKUDS OpenHarness<2026-04-13

Event History

Apr 16, 2026
CVE Published
via MITRE·12:08 AM
Data Sourced
via MITRE·12:08 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-40502?

CVE-2026-40502 is rated as a high severity vulnerability due to its capability to allow remote command injection.

2

How do I fix CVE-2026-40502?

To fix CVE-2026-40502, upgrade OpenHarness to the version after commit dd1d235 to patch the vulnerability.

3

What does CVE-2026-40502 affect?

CVE-2026-40502 affects OpenHarness prior to commit dd1d235, specifically impacting remote users with chat access.

4

Can CVE-2026-40502 be exploited remotely?

Yes, CVE-2026-40502 can be exploited remotely by users with chat access to execute sensitive administrative commands.

5

What actions can attackers take exploiting CVE-2026-40502?

Attackers exploiting CVE-2026-40502 can execute arbitrary administrative commands on the OpenHarness system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203