CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-45779

CVSS 9.3v4.0pub. 2026-06-05upd. 2026-06-10

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated remote attacker to execute arbitrary SQL statements. Exploitation requires no authentication or user interaction and can result in complete compromise of the underlying database. All deployments of Open XDMoD prior to 10.0.3 are impacted. This issue was discovered on 2023-08-03 and patched on 2023-08-04. At this time there is no evidence that this vulnerability has been exploited in the wild. The vulnerability was patched in Open XDMoD 10.0.3 on 2023-08-04. As a workaround, apply the patch manually.

🤖 AI Analysis
How it works

The vulnerability (CWE-89) consists of a lack of proper validation or parameterization of input data passed to SQL queries. An attacker can craft a malicious network request containing additional SQL instructions that will be executed by the database engine. Exploitation is possible remotely, without possessing any account in the system, which drastically lowers the barrier to entry for potential attackers.

Impact

Successful exploitation of the vulnerability can lead to complete takeover of the database — reading, modifying, or deleting data, and potentially lateral movement within the infrastructure. The consequence may be a complete breach of confidentiality, integrity, and availability of stored HPC data.

Mitigation & patch

Open XDMoD should be updated to version 10.0.3 or later (patch released 2023-08-04). For environments where immediate updating is not possible, the vendor provides manual patches: for versions 0.0.0–8.6.0 at https://open.xdmod.org/security_patches/GHSA-r33r-6g3c-r992-0_0_0-8_6_0.patch and for versions 9.0.0–10.0.2 at https://open.xdmod.org/security_patches/GHSA-r33r-6g3c-r992-9_0_0-10_0_2.patch.

Who is affected

All deployments of Open XDMoD in versions prior to 10.0.3, including versions from the 0.0.0–8.6.0 and 9.0.0–10.0.2 branches.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Buffalo Open Xdmod

    APP
    Buffalo
    < 10.0.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2026-45777CRITICAL9.3PL ✓same product

RCE poprzez command injection w Open XDMoD (wersje 9.5.0–11.0.2)

CVE-2018-16988CRITICAL9.8PL ✓same product

Open XDMoD – obejście uwierzytelnienia przez słaby mechanizm resetowania hasła

CVE-2026-45778HIGH8.6same product

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authentic...

CVE-2018-16961HIGH7.5same product

An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/dl_publication.php allows Path traversal...

CVE-2026-45776MEDIUM5.3same product

OpenXDMoD to otwarty framework do zbierania i analizowania metryk HPC. Przed wersją 11.0.3 usterka w logice ko...