CVE-2026-42785
Openkm OpenKM Community Edition, OpenKM Professional Edition
OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can submit malicious script content with an action=Evaluate parameter to execute operating system commands in the context of the OpenKM application server.
- CVSS
- 8.6
- EPSS
- 0.68% 48.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.27