Junglewise Threat Intelligence

CVE-2026-41917: OpenKM Local File Inclusion in administrative scripting interface

CVE-2026-41917 · Severity: medium · CVSS 4.9 · Published 2026-05-26

Technologies: OpenKM Community Edition, OpenKM Pro Edition. Vendors: OpenKM.

Executive brief

OpenKM, a document management system used to store and organize corporate records, contains a security flaw in its administrative interface. An authorized administrator can exploit this flaw to read any file on the underlying server, including sensitive system passwords and database credentials. This could lead to a full breach of the organization's documents and internal data.

Technical details

A local file inclusion (LFI) vulnerability exists in the OpenKM administrative scripting interface at the /admin/Scripting endpoint. The vulnerability is caused by improper validation of the 'fsPath' parameter when the 'action' parameter is set to 'Load'. An authenticated user with administrative privileges can supply arbitrary filesystem paths to read sensitive files, such as /etc/passwd, database configuration files, or JVM keystores, under the context of the OpenKM process. While the vendor has not released a formal patch, researchers recommend disabling administrative scripting and restricting filesystem access as immediate mitigations.

Affected products

  • OpenKM OpenKM Community Edition 6.3.12 and earlier
  • OpenKM OpenKM Pro Edition 7.1.47 and earlier

Timeline

  • 2026-01-16: disclosed: Initial disclosure by Terra System Labs
  • 2026-04-29: other: Exploit code published to Exploit-DB
  • 2026-05-26: advisory: NVD publication date

References

Related threats