Vulnerability Description
OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerability. Version 1.11.4 contains a patch.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open-Metadata | Openmetadata | < 1.11.4 |
Related Weaknesses (CWE)
References
- https://github.com/open-metadata/OpenMetadata/commit/bffe7c45807763f9b682021d421Patch
- https://github.com/open-metadata/OpenMetadata/security/advisories/GHSA-5f29-2333ExploitVendor Advisory
- https://github.com/open-metadata/OpenMetadata/security/advisories/GHSA-5f29-2333ExploitVendor Advisory
FAQ
What is CVE-2026-22244?
CVE-2026-22244 is a vulnerability with a CVSS score of 7.2 (HIGH). OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must ...
How severe is CVE-2026-22244?
CVE-2026-22244 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-22244?
Check the references section above for vendor advisories and patch information. Affected products include: Open-Metadata Openmetadata.