Junglewise Threat Intelligence

CVE-2026-45776: Open XDMoD broken access control in SUPReMM module

CVE-2026-45776 · Severity: info · CVSS 5.3 · Published 2026-06-05

Technologies: UBCCR Open XDMoD. Vendors: UBCCR.

Executive brief

Open XDMoD is a tool used by research institutions to track and analyze high-performance computing (HPC) usage. A security flaw in the system's access control logic allows an authenticated user to view the compute job performance and efficiency metrics of other users. This could lead to the unauthorized exposure of sensitive research activity data if the optional Job Performance (SUPReMM) module is installed.

Technical details

A vulnerability in Open XDMoD's access control logic stems from the use of a client-controlled session variable for authorization decisions. By submitting a crafted HTTPS POST request, an authenticated attacker can manipulate this session variable to bypass intended data access restrictions. This issue specifically impacts deployments utilizing the optional Job Performance (SUPReMM) module, allowing unauthorized viewing of job efficiency metrics belonging to other users. The vulnerability is addressed in version 11.0.3; a manual patch is available for users unable to upgrade immediately.

Affected products

  • ubccr Open XDMoD < 11.0.3

Timeline

  • 2026-04-06: disclosed: Privately reported to the vendor
  • 2026-05-12: patched: Fixed in version 11.0.3
  • 2026-06-05: advisory: Public advisory and CVE published

References

Related threats