OVERVIEW CVE-2026-22682 is an improper access control vulnerability affecting OpenHarness prior to commit 166fcfe. The flaw exists in built-in file tools (read_file, write_file, edit_file, and notebook_edit) due to inconsistent parameter handling in permission enforcement. This vulnerability allows attackers who can influence agent tool execution to bypass deny rules and access arbitrary files outside the intended repository scope. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.1 (HIGH) with a local attack vector requiring low privileges and no user interaction. Exploitation requires local access but can result in high-impact compromise of confidentiality and integrity. Threat actors could read sensitive files such as configuration data, credentials, and SSH keys, or create and overwrite files in restricted host paths when the tool operates in full_auto mode. EXPLOITATION STATUS Currently, there is no indication of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on vulnerability hotlists. However, the EPSS score of 0.0001 suggests relatively low probability of exploitation within the next 30 days compared to the broader CVE population. Organizations using affected OpenHarness deployments should apply the patch at commit 166fcfe or later as a precautionary measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| HKUDS | OpenHarness | >= 0, < 166fcfefb7614dbac51bd061f56542725b0298e9CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.