Description
An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.
Published: 2026-08-03
Score: 9.8 Critical
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS command injection flaw resides in the openmediavault-md plugin distributed with OpenMediaVault 8.0.4-1. The plugin fails to sanitize user input that is incorporated into shell commands, permitting an attacker to execute arbitrary commands with the privileges of the plugin process. Because the process runs as the system root user, successful exploitation elevates the attacker to full system control, enabling read, write, and delete operations on any local data and the ability to pivot to other network resources.

Affected Systems

OpenMediaVault servers that have the openmediavault-md plugin version 8.0.4-1 installed are affected. This plugin is part of the OpenMediaVault 8.0.4 release series. Systems exposed to untrusted input via the plugin’s web interface or API fall within the vulnerability scope.

Risk and Exploitability

The CVSS score of 9.8 marks the problem as critical. The EPSS score of 1% indicates a low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed, public exploitation at this time. The attack vector is likely remote, leveraging the plugin’s web interface or REST API. No special conditions beyond having the ability to send requests to the plugin endpoint are stated, so any reachable host that hosts the plugin could potentially be exploited.

Generated by OpenCVE AI on August 13, 2026 at 10:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update OpenMediaVault to a patched release that removes the command‑injection flaw.
  • Restrict network access to the openmediavault-md plugin using firewall rules, VPNs, or host‑based access controls so that only trusted hosts can reach the interface.
  • Disable or uninstall the openmediavault-md plugin if it is not essential for your environment.

Generated by OpenCVE AI on August 13, 2026 at 10:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title OpenMediaVault openmediavault-md Plugin Command Injection Leading to Root Execution

Wed, 12 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Command Injection in OpenMediaVault md Plugin Allows Root Execution
Weaknesses CWE-20

Fri, 07 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Openmediavault
Openmediavault openmediavault
Vendors & Products Openmediavault
Openmediavault openmediavault

Tue, 04 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Command Injection in OpenMediaVault md Plugin Allows Root Execution
Weaknesses CWE-20
CWE-78

Mon, 03 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.
References

Subscriptions

Openmediavault Openmediavault
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-06T15:38:36.293Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52102

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-03T21:16:40.273

Modified: 2026-08-06T22:17:41.830

Link: CVE-2026-52102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:30:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')