Executive brief
OpenKM, a document management system used to store and organize corporate records, contains a security flaw in its administrative interface. An authorized administrator can exploit this flaw to read any file on the underlying server, including sensitive system passwords and database credentials. This could lead to a full breach of the organization's documents and internal data.
Technical details
A local file inclusion (LFI) vulnerability exists in the OpenKM administrative scripting interface at the /admin/Scripting endpoint. The vulnerability is caused by improper validation of the 'fsPath' parameter when the 'action' parameter is set to 'Load'. An authenticated user with administrative privileges can supply arbitrary filesystem paths to read sensitive files, such as /etc/passwd, database configuration files, or JVM keystores, under the context of the OpenKM process. While the vendor has not released a formal patch, researchers recommend disabling administrative scripting and restricting filesystem access as immediate mitigations.
Affected products
- OpenKM OpenKM Community Edition 6.3.12 and earlier
- OpenKM OpenKM Pro Edition 7.1.47 and earlier
Timeline
- 2026-01-16: disclosed: Initial disclosure by Terra System Labs
- 2026-04-29: other: Exploit code published to Exploit-DB
- 2026-05-26: advisory: NVD publication date
References
- https://github.com/terrasystemlabs/Exploits/tree/main/OpenKM-Exploits
- https://github.com/terrasystemlabs/Exploits/tree/main/OpenKM-Exploits/nuclei-templates/openkm-local-file-execution
- https://hub.docker.com/r/openkm/openkm-ce
- https://terrasystemlabs.com/post?slug=openkm-zero-day-vulnerabilities-terra-system-labs
- https://www.exploit-db.com/exploits/52520
- https://www.openkm.com/
- https://www.vulncheck.com/advisories/openkm-local-file-inclusion-via-admin-scripting