Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6823

28
FAUCET Score

OVERVIEW CVE-2026-6823 is an insecure default configuration vulnerability in HKUDS OpenHarness prior to PR #147 remediation. The flaw allows remote channels to inherit overly permissive access controls (allow_from = ["*"]), enabling any remote sender to bypass admission checks and reach host-backed agent runtimes. This vulnerability could facilitate unauthorized access to sensitive operations and data. SEVERITY The vulnerability carries a CVSS v3.1 score of 8.2 (HIGH) with a network-based attack vector requiring no authentication, low complexity, and no user interaction. The attack surface is global (not bound to a specific scope), resulting in high confidentiality impact through potential file disclosure and read access via default-enabled tools, with limited integrity impact. The FAUCET Risk Score of 50.0/100 indicates moderate risk. EXPLOITATION STATUS The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog and shows no signs of active exploitation in the wild. The EPSS score of 0.0008 suggests minimal probability of exploitation in the next 30 days. Community attention remains low, indicating this is not a widely publicized or heavily leveraged vulnerability at this time.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.1.7CPE matchmatch criteria
cpe:2.3:a:hkuds:openharness:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.3HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
26.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 8th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / HKUDS/OpenHarness/commit/fab40c6eabfb15f2bdf23cddd3cfe66a64ea203d
Patch
github.com / HKUDS/OpenHarness/pull/147
ExploitIssue TrackingPatch
github.com / HKUDS/OpenHarness/releases/tag/v0.1.7
Release Notes
vulncheck.com / advisories/hkuds-openharness-insecure-default-remote-channel-allowlist
Third Party Advisory