CVE-2022-26833 is an improper authentication vulnerability in the REST API of Open Automation Software (OAS) Platform V16.00.0121, allowing unauthenticated access through specially crafted HTTP requests. This critical vulnerability has a CVSS score of 9.4, indicating a network-exploitable flaw with low attack complexity, leading to high impact on confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, exploit intelligence shows available Nuclei templates and significant community discussion, with media coverage highlighting its potential for critical remote code execution.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.00.0112CPE matchmatch criteria | cpe:2.3:a:openautomationsoftware:oas_platform:16.00.0112:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.