CVE-2024-11220: Openautomationsoftware Open Automation Software
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation.
Affected products
- Openautomationsoftware Open Automation Software: before 20.0.0.76 (fixed in 20.0.0.76)
Published 2024-12-06. Last modified 2026-06-17.