CVE-2026-6729 Details
Description
HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exploiting a shared ohmo session key that lacks sender identity verification. Attackers can reuse another user's conversation state and replace or interrupt their active tasks by colliding into the same session boundary through the shared chat or thread scope.
A session key derivation vulnerability has been identified in HKUDS OpenHarness versions prior to the PR #159 remediation. This vulnerability allows authenticated users in shared chats or threads to hijack the sessions of other users. The issue arises from a shared session key that does not verify sender identity, enabling attackers to reuse another user's conversation state and disrupt their ongoing tasks by interfering with the same session boundary within the shared chat or thread.
Users are advised to update to the version of HKUDS OpenHarness that includes the PR #159 remediation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/HKUDS/OpenHarness/pull/159 | CISA-ADP | ExploitIssue Tracking |
| https://github.com/HKUDS/OpenHarness/commit/3186851c479ee714a9bb9aa6cd77017db7e589e2 | [email protected] | Patch |
| https://github.com/HKUDS/OpenHarness/pull/159 | [email protected] | ExploitIssue Tracking |
| https://www.vulncheck.com/advisories/hkuds-openharness-session-key-collision-privilege-escalation | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hkuds openharness | < 0.1.7 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | Initial Analysis | [email protected] |
| Apr 21, 2026 | CVE Modified | CISA-ADP |
| Apr 20, 2026 | New CVE Received | [email protected] |