PT-2026-43254 · Openkm · Openkm

Published

2026-05-26

·

Updated

2026-05-26

·

CVE-2026-42425

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenKM version 6.3.12
Description Authenticated administrative users can execute arbitrary SQL statements against the application database through the DatabaseQuery interface. By submitting malicious SQL queries via the qs parameter to the '/admin/DatabaseQuery' endpoint, an attacker can extract sensitive data from the OKM USER table, such as usernames and password hashes, modify permissions, or delete database records.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-42425

Affected Products

Openkm