HarborGuard / CVE
Back to search
HIGHCVE-2026-6819Published Modified CNA VulnCheck

CVE-2026-6819: HKUDS OpenHarness Plugin Management Command Exposure

HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /reload-plugins to remote senders by default. Attackers who gain access through the channel layer can remotely manage plugin trust and activation state, enabling unauthorized plugin installation and activation on the system.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
PR #156
Affected Products
1

Fix available

PR #156
Patch commits
Affected packages
  • HKUDS / OpenHarness
    < PR #156 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N