CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-45777

CVSS 9.3v4.0pub. 2026-06-05upd. 2026-06-10

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system commands on the web server hosting Open XDMoD with the privileges of the web server process. This could allow an attacker to read or modify application data, alter system configuration, or disrupt service availability. All deployments of Open XDMoD versions 9.5.0 through 11.0.2 (inclusive) are impacted. This issue was reported privately on 2026-04-06, and at this time there is no evidence that this vulnerability has been exploited in the wild. The vulnerability was patched in Open XDMoD 11.0.3 on 2026-05-12. As a workaround, apply the patch manually.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-78 (OS Command Injection) allows an unauthenticated attacker to send a crafted request to the web server, resulting in the execution of arbitrary system commands with the permissions of the web server process. The bug was introduced in version 9.5.0 and was not removed until version 11.0.3 was released. The attack is possible remotely, without user interaction, and without requiring elevated privileges.

Impact

An attacker can read or modify application data, change operating system configuration, and disrupt service availability. Successful exploitation of the vulnerability provides practically full control over the web server within the scope of its process permissions.

Mitigation & patch

Update Open XDMoD to version 11.0.3 (released 2026-05-12). As a temporary solution, the vendor has provided a patch that can be applied manually: https://open.xdmod.org/security_patches/GHSA-29qm-7w4v-43fw-9_5_0-11_0_2.patch

Who is affected

Open XDMoD versions 9.5.0 through 11.0.2 inclusive

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Buffalo Open Xdmod

    APP
    Buffalo
    9.5.0 – 11.0.3 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2026-45779CRITICAL9.3PL ✓same product

SQL Injection w Open XDMoD — nieuwierzytelniony dostęp do bazy danych

CVE-2018-16988CRITICAL9.8PL ✓same product

Open XDMoD – obejście uwierzytelnienia przez słaby mechanizm resetowania hasła

CVE-2026-45778HIGH8.6same product

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authentic...

CVE-2018-16961HIGH7.5same product

An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/dl_publication.php allows Path traversal...

CVE-2026-45776MEDIUM5.3same product

OpenXDMoD to otwarty framework do zbierania i analizowania metryk HPC. Przed wersją 11.0.3 usterka w logice ko...