OVERVIEW CVE-2026-6823 is an insecure default configuration vulnerability in HKUDS OpenHarness prior to PR #147 remediation. The flaw allows remote channels to inherit overly permissive access controls (allow_from = ["*"]), enabling any remote sender to bypass admission checks and reach host-backed agent runtimes. This vulnerability could facilitate unauthorized access to sensitive operations and data. SEVERITY The vulnerability carries a CVSS v3.1 score of 8.2 (HIGH) with a network-based attack vector requiring no authentication, low complexity, and no user interaction. The attack surface is global (not bound to a specific scope), resulting in high confidentiality impact through potential file disclosure and read access via default-enabled tools, with limited integrity impact. The FAUCET Risk Score of 50.0/100 indicates moderate risk. EXPLOITATION STATUS The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog and shows no signs of active exploitation in the wild. The EPSS score of 0.0008 suggests minimal probability of exploitation in the next 30 days. Community attention remains low, indicating this is not a widely publicized or heavily leveraged vulnerability at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.7CPE matchmatch criteria | cpe:2.3:a:hkuds:openharness:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.