Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-22682

25
FAUCET Score

OVERVIEW CVE-2026-22682 is an improper access control vulnerability affecting OpenHarness prior to commit 166fcfe. The flaw exists in built-in file tools (read_file, write_file, edit_file, and notebook_edit) due to inconsistent parameter handling in permission enforcement. This vulnerability allows attackers who can influence agent tool execution to bypass deny rules and access arbitrary files outside the intended repository scope. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.1 (HIGH) with a local attack vector requiring low privileges and no user interaction. Exploitation requires local access but can result in high-impact compromise of confidentiality and integrity. Threat actors could read sensitive files such as configuration data, credentials, and SSH keys, or create and overwrite files in restricted host paths when the tool operates in full_auto mode. EXPLOITATION STATUS Currently, there is no indication of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on vulnerability hotlists. However, the EPSS score of 0.0001 suggests relatively low probability of exploitation within the next 30 days compared to the broader CVE population. Organizations using affected OpenHarness deployments should apply the patch at commit 166fcfe or later as a precautionary measure.

Impacted Technologies

VendorProductVersion(s)CPE
HKUDSOpenHarness
>= 0, < 166fcfefb7614dbac51bd061f56542725b0298e9CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

8.4HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
2.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 13th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / HKUDS/OpenHarness/commit/166fcfefb7614dbac51bd061f56542725b0298e9
github.com / HKUDS/OpenHarness/pull/32
vulncheck.com / advisories/openharness-improper-access-control-via-file-tools