PT-2026-34065 · Hkuds+1 · Openharness
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenHarness versions prior to PR #156
Description
Plugin lifecycle commands are exposed to remote senders by default. This allows attackers who gain access through the channel layer to remotely manage plugin trust and activation states, which can lead to unauthorized plugin installation and activation on the system. The affected API endpoints include '/plugin install', '/plugin enable', '/plugin disable', and '/reload-plugins'.
Recommendations
Update to the version containing PR #156 remediation.
Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openharness