CVE-2026-26002: Osc Open Ondemand
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when navigating to a directory. This has been patched in versions 4.0.9 and 4.1.3. Versions below this remain susceptible.
Affected products
- Osc Open Ondemand: before 3.1.16 (fixed in 3.1.16); from 4.0.0, before 4.0.9 (fixed in 4.0.9); from 4.1.0, before 4.1.3 (fixed in 4.1.3)
Published 2026-03-04. Last modified 2026-06-17.