CVE-2026-6819 is a remote code execution vulnerability in HKUDS OpenHarness versions prior to PR #156 that exposes critical plugin lifecycle management commands including /plugin install, /plugin enable, /plugin disable, and /reload-plugins to unauthenticated remote attackers. This exposure allows adversaries who gain access to the channel layer to remotely install unauthorized plugins and manipulate plugin activation states without legitimate authorization. The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring no authentication or user interaction, making it trivial for attackers to exploit. Successful exploitation results in complete compromise of system confidentiality, integrity, and availability through arbitrary plugin execution and system control. While CVE-2026-6819 does not currently appear in the Known Exploited Vulnerabilities catalog, it is actively listed on security tracking platforms and demonstrates elevated community attention relative to other CVEs. Organizations running vulnerable versions of OpenHarness should prioritize patching to PR #156 or later given the critical nature of remote unauthenticated code execution capabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.7CPE matchmatch criteria | cpe:2.3:a:hkuds:openharness:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.