Executive brief
Open XDMoD, a tool used to analyze performance metrics for high-performance computing (HPC) clusters, contains a critical security flaw. An unauthorized attacker can remotely take control of the web server hosting the application. This could lead to the theft of sensitive research data, unauthorized modification of system settings, or a complete shutdown of the monitoring service.
Technical details
An OS command injection vulnerability (CWE-78) exists in Open XDMoD versions 9.5.0 through 11.0.2. The flaw allows an unauthenticated remote attacker to execute arbitrary system commands via the web interface with the privileges of the web server process. This is achieved by sending specially crafted requests that bypass input neutralization for OS commands. Successful exploitation grants the attacker full control over the application environment, including the ability to read/modify data and disrupt services. The issue is resolved in version 11.0.3, and a manual patch is available for older installations.
Affected products
- ubccr Open XDMoD 9.5.0 to 11.0.2
Timeline
- 2026-04-06: disclosed: Reported privately
- 2026-05-12: patched: Fixed in version 11.0.3
- 2026-06-05: advisory: NVD publication date