CVE-2026-52102 Details
Description
An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.
A command injection vulnerability has been identified in the OpenMediaVault RAID management plugin, specifically in versions through 8.0.4-1. This vulnerability allows authenticated administrators to execute arbitrary commands as root on the underlying system. The issue arises from inadequate sanitization of RAID parameters before they are passed to a command execution helper, enabling the injection of shell metacharacters into the command line. The vulnerability can be exploited via an HTTP POST request to the RPC service, potentially without direct access to administrative credentials.
Users are advised to update to the openmediavault-md release that includes the fix for this vulnerability. Additionally, access to the web administration interface should be restricted to trusted management networks, and OpenMediaVault should not be exposed directly to the Internet. It is also recommended to limit the number of administrative accounts and enforce strong authentication.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 3, 2026CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/NtGabrielGomes/46817d363821cf8c5ff4882c811a4325 | [email protected] | AdvisoryRemedy |
| https://github.com/openmediavault/openmediavault | [email protected] | Source CodeVendor |
| https://www.openmediavault.org | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| OpenMediaVault | <= 8.0.4-1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | [email protected] |
Volerion