CVE 5.3 MEDIUM

HKUDS OpenHarness Session Key Collision Privilege Escalation_CVE-2026-6729

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Description

HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exploiting a shared ohmo session key that lacks sender identity verification. Attackers can reuse another user's conversation state and replace or interrupt their active tasks by colliding into the same session boundary through the shared chat or thread scope.

Basic Information

ID CVE-2026-6729
Source VulnCheck
Published Apr 20, 2026 at 22:01

Affected Product

Vendor HKUDS
Product OpenHarness
Affected Versions HKUDS OpenHarness 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.