PT-2026-2180 · Unknown · Openmetadata

Lnlinh31

·

Published

2026-01-07

·

Updated

2026-01-08

·

CVE-2026-22244

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions OpenMetadata versions prior to 1.11.4
Description OpenMetadata is a unified metadata platform susceptible to remote code execution through Server-Side Template Injection (SSTI) within FreeMarker email templates. Exploitation requires an attacker to possess administrative privileges. The vulnerability resides in how email templates are processed, potentially allowing malicious code execution.
Recommendations Update to version 1.11.4 or later.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-22244
GHSA-5F29-2333-H9C7

Affected Products

Openmetadata