OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system commands on the web server hosting Open XDMoD with the privileges of the web server process. This could allow an attacker to read or modify application data, alter system configuration, or disrupt service availability. All deployments of Open XDMoD versions 9.5.0 through 11.0.2 (inclusive) are impacted. This issue was reported privately on 2026-04-06, and at this time there is no evidence that this vulnerability has been exploited in the wild. The vulnerability was patched in Open XDMoD 11.0.3 on 2026-05-12. As a workaround, apply the patch manually.
The vulnerability classified as CWE-78 (OS Command Injection) allows an unauthenticated attacker to send a crafted request to the web server, resulting in the execution of arbitrary system commands with the permissions of the web server process. The bug was introduced in version 9.5.0 and was not removed until version 11.0.3 was released. The attack is possible remotely, without user interaction, and without requiring elevated privileges.
An attacker can read or modify application data, change operating system configuration, and disrupt service availability. Successful exploitation of the vulnerability provides practically full control over the web server within the scope of its process permissions.
Update Open XDMoD to version 11.0.3 (released 2026-05-12). As a temporary solution, the vendor has provided a patch that can be applied manually: https://open.xdmod.org/security_patches/GHSA-29qm-7w4v-43fw-9_5_0-11_0_2.patch
Open XDMoD versions 9.5.0 through 11.0.2 inclusive
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XBuffalo Open Xdmod
APPBuffalo9.5.0 – 11.0.3 (excl.)
Related vulnerabilities
SQL Injection w Open XDMoD — nieuwierzytelniony dostęp do bazy danych
Open XDMoD – obejście uwierzytelnienia przez słaby mechanizm resetowania hasła
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authentic...
An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/dl_publication.php allows Path traversal...
OpenXDMoD to otwarty framework do zbierania i analizowania metryk HPC. Przed wersją 11.0.3 usterka w logice ko...