CVE-2026-6729: HKUDS OpenHarness Session Key Collision Privilege Escalation
HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exploiting a shared ohmo session key that lacks sender identity verification. Attackers can reuse another user's conversation state and replace or interrupt their active tasks by colliding into the same session boundary through the shared chat or thread scope.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HKUDS OpenHarnessto a version that resolves this vulnerability.Patch PR #159
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6729?
CVE-2026-6729 has a critical severity rating due to its potential for privilege escalation and session hijacking.
How do I fix CVE-2026-6729?
To fix CVE-2026-6729, update HKUDS OpenHarness to the version that includes PR #159.
Who is affected by CVE-2026-6729?
Authenticated users in shared chats or threads using HKUDS OpenHarness prior to PR #159 are affected by CVE-2026-6729.
What is the main vulnerability described in CVE-2026-6729?
CVE-2026-6729 describes a session key derivation vulnerability that allows session hijacking between users.
Can CVE-2026-6729 be exploited remotely?
Yes, CVE-2026-6729 can be exploited by authenticated users in the same chat or thread, allowing for local privilege escalation.