CVE-2024-8260 is a high-severity SMB force-authentication vulnerability affecting all versions of Open Policy Agent (OPA) for Windows prior to v0.68.0. This flaw stems from improper input validation, allowing a malicious actor to supply an arbitrary SMB share instead of a legitimate Rego file to OPA CLI or library functions. The CVSS score of 7.3 indicates a high impact on confidentiality, integrity, and availability, requiring local access and user interaction for exploitation. While the vulnerability has a low EPSS score and is not listed in CISA's KEV catalog, suggesting no active widespread exploitation, there is no public exploit code available, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.68.0CPE matchmatch criteria | cpe:2.3:a:openpolicyagent:open_policy_agent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
OPA for Windows has an SMB force-authentication vulnerability
Aug 30, 2024opa: OPA SMB Force-Authentication
Aug 30, 2024OPA SMB Force-Authentication
Aug 30, 2024OPA SMB Force-Authentication
Aug 30, 2024OPA SMB Force-Authentication
Aug 30, 2024