CVE-2026-45776
Last modified
CVE-2026-45776 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's access control logic allows an attacker to submit a crafted HTTPS POST request that sets a session variable used for authorization decisions. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's access control logic allows an attacker to submit a crafted HTTPS POST request that sets a session variable used for authorization decisions. If an installation of Open XDMoD includes the optional Job Performance (SUPReMM) module, an attacker could bypass intended data access restrictions and view other users' compute job efficiency metrics. All deployments of Open XDMoD prior to version 11.0.3 that contain the optional Job Performance (SUPReMM) module are impacted. This issue was reported privately on 2026-04-06, and at this time there is no evidence that this vulnerability has been exploited in the wild. The vulnerability was patched in Open XDMoD 11.0.3 on 2026-05-12. As a workaround, apply the patch manually.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Buffalo | Open Xdmod | < 11.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-45776?
How severe is CVE-2026-45776?
How do I fix CVE-2026-45776?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-45760(Externally Controlled Reference to a Resource in Another Sp…8.1
- CVE-2026-4577A vulnerability was found in code-projects Exam Form Submiss…2.4
- CVE-2026-45771FreeSWITCH is a Software Defined Telecom Stack enabling the …7.5
- CVE-2026-45772Turborepo is a high-performance build system for JavaScript …9.8
- CVE-2026-45773Turborepo is a high-performance build system for JavaScript …6.5
- CVE-2026-45775Discourse is an open-source discussion platform. From versio…6.8
- CVE-2026-45777OpenXDMoD is an open framework for collecting and analyzing …9.8
- CVE-2026-45778OpenXDMoD is an open framework for collecting and analyzing …5.4
- CVE-2026-45779OpenXDMoD is an open framework for collecting and analyzing …9.8
- CVE-2026-4578A vulnerability was determined in code-projects Exam Form Su…2.4
- CVE-2026-45780Discourse is an open-source discussion platform. Prior to 20…4.3
- CVE-2026-45781The MCP Registry provides MCP clients with a list of MCP ser…3.5
Are you affected by CVE-2026-45776?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
