PT-2026-23070 · Unknown · Open Ondemand

·

CVE-2026-26002

·

Published

2026-03-04

·

Updated

2026-03-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open OnDemand versions prior to 4.0.9 Open OnDemand versions prior to 4.1.3
Description The Files application in Open OnDemand is susceptible to malicious input when navigating to a directory. This issue affects installations prior to versions 4.0.9 and 4.1.3.
Recommendations Update to Open OnDemand version 4.0.9 or later. Update to Open OnDemand version 4.1.3 or later.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26002
GHSA-F83Q-MHRR-3CR2

Affected Products

Open Ondemand