Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-8260

26
FAUCET Score

CVE-2024-8260 is a high-severity SMB force-authentication vulnerability affecting all versions of Open Policy Agent (OPA) for Windows prior to v0.68.0. This flaw stems from improper input validation, allowing a malicious actor to supply an arbitrary SMB share instead of a legitimate Rego file to OPA CLI or library functions. The CVSS score of 7.3 indicates a high impact on confidentiality, integrity, and availability, requiring local access and user interaction for exploitation. While the vulnerability has a low EPSS score and is not listed in CISA's KEV catalog, suggesting no active widespread exploitation, there is no public exploit code available, and community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.68.0CPE matchmatch criteria
cpe:2.3:a:openpolicyagent:open_policy_agent:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
1.3
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
26.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 59th percentile among its peer group of 759 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

gopatch availablevia ghsa
Product: github.com/open-policy-agent/opaFixed in: 0.68.0
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.4Fixed in: rhosdt/tempo-gateway-opa-rhel8:sha256:878871eb4c91180b2c4633ad7c40d0800349c665fe0c708e5c2e0e1f8d35c48c
View patch
dotnetvendor investigatingvia llm_extracted
langgeniusvendor investigatingvia llm_extracted
ranchervendor investigatingvia llm_extracted
redhatno patchvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/tempo-gateway-opa-rhel8
redhatno patchvia redhat_api
Product: Red Hat Connectivity Link 1Fixed in: authorino-container

Vendor Advisories (5)

goGHSA-c77r-fh37-x2pxmedium

OPA for Windows has an SMB force-authentication vulnerability

Aug 30, 2024
redhatCVE-2024-8260Moderate

opa: OPA SMB Force-Authentication

Aug 30, 2024
rancherllm-rancher-920f6e8a8c5c7164MEDIUM

OPA SMB Force-Authentication

Aug 30, 2024
langgeniusllm-langgenius-ae9e771bfbc6d941MEDIUM

OPA SMB Force-Authentication

Aug 30, 2024
dotnetllm-dotnet-ef96a3c542f56fc7MEDIUM

OPA SMB Force-Authentication

Aug 30, 2024

References

tenable.com / security/research/tra-2024-36
Third Party Advisory