CVE-2017-1000081: Onosproject Onos

Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.

Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.

Affected products

  • Onosproject Onos: version 1.8.0 only; version 1.9.0 only

Published 2017-07-17. Last modified 2026-06-17.