PT-2026-23070 · Unknown · Open Ondemand

Iratechiapet

·

Published

2026-03-04

·

Updated

2026-03-05

·

CVE-2026-26002

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open OnDemand versions prior to 4.0.9 Open OnDemand versions prior to 4.1.3
Description The Files application in Open OnDemand is susceptible to malicious input when navigating to a directory. This issue affects installations prior to versions 4.0.9 and 4.1.3.
Recommendations Update to Open OnDemand version 4.0.9 or later. Update to Open OnDemand version 4.1.3 or later.

Exploit

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-26002
GHSA-F83Q-MHRR-3CR2

Affected Products

Open Ondemand