SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-52102

CRITICAL · CVSS 9.8 EPSS 1.76% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The openmediavault-md plugin in OpenMediaVault v8.0.4-1 is vulnerable to an OS command injection, enabling attackers to execute arbitrary commands with root privileges by injecting shell metacharacters. This poses a significant risk to system integrity and confidentiality. Users of OpenMediaVault, particularly those utilizing the affected plugin, should prioritize patching or mitigating this vulnerability to safeguard their systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-52102
Severity
CRITICAL
CVSS
9.8
EPSS
1.76%

Original NVD Description

An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.