CVE-2026-6823 Details
Description
HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote channels inherit allow_from = ["*"] permitting arbitrary remote senders to pass admission checks. Attackers who can reach the configured channel can bypass access controls and reach host-backed agent runtimes, potentially leading to unauthorized file disclosure and read access through default-enabled read-only tools.
A vulnerability exists in HKUDS OpenHarness versions prior to the PR #147 remediation, where remote channels are assigned an insecure default allowlist. This configuration allows arbitrary remote senders to bypass admission checks and access host-backed agent runtimes. Such access could lead to unauthorized file disclosures and read access through default-enabled read-only tools.
Users can update to OpenHarness version 0.1.7 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/HKUDS/OpenHarness/pull/147 | CISA-ADP | ExploitIssue TrackingPatch |
| https://github.com/HKUDS/OpenHarness/commit/fab40c6eabfb15f2bdf23cddd3cfe66a64ea203d | [email protected] | Patch |
| https://github.com/HKUDS/OpenHarness/pull/147 | [email protected] | ExploitIssue TrackingPatch |
| https://github.com/HKUDS/OpenHarness/releases/tag/v0.1.7 | [email protected] | Release Notes |
| https://www.vulncheck.com/advisories/hkuds-openharness-insecure-default-remote-channel-allowlist | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hkuds openharness | < 0.1.7 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 7, 2026 | Initial Analysis | [email protected] |
| Apr 22, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | New CVE Received | [email protected] |