← Browse

CVE-2026-22244

Medium

Elevated severity or exploit probability.

CVSS base
7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
1.3%
69.3th percentile
CISA KEV
Not listed
Weakness / dates
CWE-94
Published 2026-01-08 · modified 2026-08-31

Description

OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerability. Version 1.11.4 contains a patch.

Affected

open-metadata

References

Official: NVD · CVE.org