Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openkm openkm Community Edition
Openkm openkm Professional Edition |
|
| Vendors & Products |
Openkm openkm Community Edition
Openkm openkm Professional Edition |
Tue, 26 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scripting that allows authenticated administrators to read arbitrary files by supplying an attacker-controlled filesystem path through the fsPath parameter with action=Load. Attackers can exploit this to access sensitive files including /etc/passwd, configuration files containing database credentials, and JVM keystores accessible to the OpenKM process. | |
| Title | OpenKM 6.3.12 Local File Inclusion via Admin Scripting | |
| First Time appeared |
Openkm
Openkm openkm |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:openkm:openkm:*:*:*:*:community:*:*:* cpe:2.3:a:openkm:openkm:*:*:*:*:professional:*:*:* |
|
| Vendors & Products |
Openkm
Openkm openkm |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-27T16:08:59.835Z
Reserved: 2026-04-22T15:20:49.860Z
Link: CVE-2026-41917
Updated: 2026-05-27T16:08:54.808Z
Status : Deferred
Published: 2026-05-26T15:16:36.440
Modified: 2026-06-17T10:47:11.720
Link: CVE-2026-41917
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:05:11Z