Vulnerability Description
OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can submit malicious script content with an action=Evaluate parameter to execute operating system commands in the context of the OpenKM application server.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/terrasystemlabs/Exploits/tree/main/OpenKM-Exploits
- https://github.com/terrasystemlabs/Exploits/tree/main/OpenKM-Exploits/nuclei-tem
- https://hub.docker.com/r/openkm/openkm-ce
- https://terrasystemlabs.com/post?slug=openkm-zero-day-vulnerabilities-terra-syst
- https://www.exploit-db.com/exploits/52520
- https://www.openkm.com/
- https://www.vulncheck.com/advisories/openkm-remote-code-execution-via-administra
FAQ
What is CVE-2026-42785?
CVE-2026-42785 is a vulnerability with a CVSS score of 7.2 (HIGH). OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can subm...
How severe is CVE-2026-42785?
CVE-2026-42785 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-42785?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.