CVE-2026-6819 Details
Description
HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /reload-plugins to remote senders by default. Attackers who gain access through the channel layer can remotely manage plugin trust and activation state, enabling unauthorized plugin installation and activation on the system.
A vulnerability in HKUDS OpenHarness prior to the PR #156 remediation allows plugin lifecycle commands, such as '/plugin install', '/plugin enable', '/plugin disable', and '/reload-plugins', to be exposed to remote senders by default. This exposure enables attackers with access through the channel layer to manage plugin trust and activation states remotely, potentially leading to unauthorized installation and activation of plugins on the system.
Users can update to HKUDS OpenHarness version 0.1.7 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/HKUDS/OpenHarness/pull/156 | CISA-ADP | ExploitIssue TrackingPatch |
| https://github.com/HKUDS/OpenHarness/commit/59017e09880fcf9a6f60456a84fb982900b2c0b2 | [email protected] | Patch |
| https://github.com/HKUDS/OpenHarness/pull/156 | [email protected] | ExploitIssue TrackingPatch |
| https://github.com/HKUDS/OpenHarness/releases/tag/v0.1.7 | [email protected] | Release Notes |
| https://www.vulncheck.com/advisories/hkuds-openharness-plugin-management-command-exposure | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hkuds openharness | < 0.1.7 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 7, 2026 | Initial Analysis | [email protected] |
| Apr 22, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | New CVE Received | [email protected] |