CVE-2026-22244: Open-Metadata Openmetadata

High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.

OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerability. Version 1.11.4 contains a patch.

Affected products

Published 2026-01-08. Last modified 2026-08-31.