CVE 8.7 HIGH

HKUDS OpenHarness Plugin Management Command Exposure_CVE-2026-6819

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /reload-plugins to remote senders by default. Attackers who gain access through the channel layer can remotely manage plugin trust and activation state, enabling unauthorized plugin installation and activation on the system.

AI Analysis

Exposure of plugin lifecycle commands to remote senders, allowing unauthorized plugin installation and activation

Basic Information

ID CVE-2026-6819
Source VulnCheck
Published Apr 21, 2026 at 19:41

Affected Product

Vendor HKUDS
Product OpenHarness
Affected Versions HKUDS OpenHarness 0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor HKUDS
Product OpenHarness

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.