PT-2026-34183 · Hkuds · Openharness

Tjb-Tech

·

Published

2026-04-21

·

Updated

2026-04-26

·

CVE-2026-6823

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenHarness versions prior to PR #147
Description An insecure default configuration exists where remote channels inherit allow from = ["*"], which allows arbitrary remote senders to pass admission checks. Attackers capable of reaching the configured channel can bypass access controls to reach host-backed agent runtimes. This may result in unauthorized file disclosure and read access via default-enabled read-only tools.
Recommendations Apply the remediation provided in PR #147.

Exploit

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2026-6823

Affected Products

Openharness