CVE detail
CVE-2026-42785
OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can submit malicious script content with an action=Evaluate parameter to execute operating system commands in the context of the OpenKM application server.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 16.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- https://www.vulncheck.com/advisories/openkm-remote-code-execution-via-administrative-scriptingwww.vulncheck.com
No excerpt available.
Exploitwww.vulncheck.comMay 26, 2026, 3:16 PM - https://www.openkm.com/www.openkm.com
No excerpt available.
referencewww.openkm.comMay 26, 2026, 3:16 PM - https://www.exploit-db.com/exploits/52520www.exploit-db.com
No excerpt available.
Exploitwww.exploit-db.comMay 26, 2026, 3:16 PM - https://terrasystemlabs.com/post?slug=openkm-zero-day-vulnerabilities-terra-system-labsterrasystemlabs.com
No excerpt available.
referenceterrasystemlabs.comMay 26, 2026, 3:16 PM - https://hub.docker.com/r/openkm/openkm-cehub.docker.com
No excerpt available.
referencehub.docker.comMay 26, 2026, 3:16 PM No excerpt available.
Exploitgithub.comMay 26, 2026, 3:16 PMNo excerpt available.
Exploitgithub.comMay 26, 2026, 3:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-56747CVSS 8.7 · High
Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execut…
- CVE-2026-14289CVSS 9.0 · Critical
The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic…
- CVE-2026-63720CVSS 7.5 · High
datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supply…
- CVE-2026-65693CVSS 8.6 · High
Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecti…
- CVE-2026-16801CVSS 8.8 · High
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with varia…
- CVE-2026-16800CVSS 8.8 · High
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedu…