Junglewise Threat Intelligence

CVE-2026-22244: OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template

CVE-2026-22244 · Severity: critical · CVSS 9.1 · Published 2026-01-08

Technologies: Open Metadata OpenMetadata. Vendors: Maven.

Executive brief

OpenMetadata is a metadata management and data governance platform. An admin-authenticated attacker can inject malicious FreeMarker template code into email templates stored in the database, leading to remote code execution on the server when emails are sent. This allows an attacker to execute arbitrary commands with the privileges of the OpenMetadata process, potentially compromising the entire system including databases and connected data sources.

Technical details

The vulnerability is a server-side template injection (SSTI) in the DefaultTemplateProvider.getTemplate() method. User-supplied email templates are loaded from the database and rendered with FreeMarker using an unsafe Configuration object that does not enable TemplateClassResolver.SAFER_RESOLVER or disable API built-ins. An attacker with admin privileges can use the PATCH /api/v1/docStore/{templateId} endpoint to inject FreeMarker directives like <#assign ex="freemarker.template.utility.Execute"?new()>, which instantiate the Execute class and run shell commands. The malicious template is triggered when emails are sent (e.g., via password reset, user invitations, or test email endpoints). Commands execute as the OpenMetadata server process user, potentially exposing environment variables, database credentials, and allowing further lateral movement.

Affected products

  • Open Metadata OpenMetadata >= 1.5.0, < 1.11.4

Timeline

  • 2026-01-07: disclosed: GitHub Advisory published
  • 2026-01-07: advisory: CVE-2026-22244 / GHSA-5f29-2333-h9c7 released
  • 2026-01-07: patched: Patched in version 1.11.4

References