Wisc maintains HTCondor, a widely deployed distributed computing and workload management system that sits in a prominent position within high-performance computing and research infrastructure, presenting a high-value target for attackers seeking to compromise computational resources and data. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including improper input validation, authentication and authorization flaws, and cleartext transmission of sensitive information that reflect the system's role in orchestrating trusted compute environments. Defenders should treat updates to this system as a priority given its position in computational pipelines and the sensitivity of workloads it manages; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wisc over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18823CRITICAL HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job | Apr 27, 2020 | 9.8 | 32 | NO | NO |
CVE-2022-26110HIGH An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the | Apr 6, 2022 | 8.8 | 29 | NO | NO |
CVE-2021-25311CRITICAL condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, as demonstrated by creating a file under /etc that will late | Jan 27, 2021 | 9.9 | 28 | NO | NO |
CVE-2012-3490HIGH The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen.cpp and the (3) systemCommand function in condor_vm-gahp/vmgahp_common.cpp in Condor 7.6.x before 7. | Jan 9, 2020 | 8.8 | 28 | NO | NO |
CVE-2021-45103HIGH An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S3 cloud storage that a user has asked HTCondor to transfer. | Apr 6, 2022 | 8.1 | 26 | NO | NO |
CVE-2021-45101HIGH An issue was discovered in HTCondor before 8.8.15, 9.0.x before 9.0.4, and 9.1.x before 9.1.2. Using standard command-line tools, a user with only READ access to an HTCondor SchedD | Dec 16, 2021 | 8.1 | 26 | NO | NO |
CVE-2021-25312HIGH HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS authentication method. | Jan 27, 2021 | 8.8 | 26 | NO | NO |
CVE-2014-8126HIGH The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code. | Jan 31, 2020 | 8.8 | 25 | NO | NO |
CVE-2021-45104HIGH An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor network data can interfere with users' jobs and data. | Apr 6, 2022 | 7.4 | 24 | NO | NO |
CVE-2025-30093HIGH HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions. | Mar 27, 2025 | 8.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wisc.
Media articles that mention a CVE ID that affects a product developed by Wisc — matched by CVE ID, not by vendor name.