CVE-2026-52102

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.

Published 2026-08-03. Last modified 2026-09-09.