CVE Explorer
CVE-2026-45779
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated remote attacker to execute arbitrary SQL statements. Exploitation requires no authentication or user interaction and can result in complete compromise of the underlying database. All deployments of Open XDMoD prior to 10.0.3 are impacted. This issue was discovered on 2023-08-03 and patched on 2023-08-04. At this time
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"xdmod","vendor":"ubccr","versions":[{"status":"affected","version":"< 10.0.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:16127d45f00475e30b9b79f17532fda2e3e18133cc10fac9d37244a83f9e26ba · sha256:959e9acc36e2452f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:16127d45f00475e30b9b79f17532fda2e3e18133cc10fac9d37244a83f9e26ba · sha256:959e9acc36e2452f… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-89","description":"CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:16127d45f00475e30b9b79f17532fda2e3e18133cc10fac9d37244a83f9e26ba · sha256:959e9acc36e2452f… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/ubccr/xdmod/releases/tag/v10.0.3","tags":["x_refsource_MISC"],"url":"https://github.com/ubccr/xdmod/releases/tag/v10.0.3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:16127d45f00475e30b9b79f17532fda2e3e18133cc10fac9d37244a83f9e26ba · sha256:959e9acc36e2452f… · /containers/cna/references/1
{"name":"https://github.com/ubccr/xdmod/security/advisories/GHSA-r33r-6g3c-r992","tags":["x_refsource_CONFIRM"],"url":"https://github.com/ubccr/xdmod/security/advisories/GHSA-r33r-6g3c-r992"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:16127d45f00475e30b9b79f17532fda2e3e18133cc10fac9d37244a83f9e26ba · sha256:959e9acc36e2452f… · /containers/cna/references/0
{"name":"https://open.xdmod.org/security_patches/GHSA-r33r-6g3c-r992-0_0_0-8_6_0.patch","tags":["x_refsource_MISC"],"url":"https://open.xdmod.org/security_patches/GHSA-r33r-6g3c-r992-0_0_0-8_6_0.patch"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:16127d45f00475e30b9b79f17532fda2e3e18133cc10fac9d37244a83f9e26ba · sha256:959e9acc36e2452f… · /containers/cna/references/2
{"name":"https://open.xdmod.org/security_patches/GHSA-r33r-6g3c-r992-9_0_0-10_0_2.patch","tags":["x_refsource_MISC"],"url":"https://open.xdmod.org/security_patches/GHSA-r33r-6g3c-r992-9_0_0-10_0_2.patch"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:16127d45f00475e30b9b79f17532fda2e3e18133cc10fac9d37244a83f9e26ba · sha256:959e9acc36e2452f… · /containers/cna/references/3
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.