Unknown · Openmetadata · CVE-2026-22244
**Name of the Vulnerable Software and Affected Versions**
OpenMetadata versions prior to 1.11.4
**Description**
OpenMetadata is a unified metadata platform susceptible to remote code execution through Server-Side Template Injection (SSTI) within FreeMarker email templates. Exploitation requires an attacker to possess administrative privileges. The vulnerability resides in how email templates are processed, potentially allowing malicious code execution.
**Recommendations**
Update to version 1.11.4 or later.