CVE-2026-22244

HIGH

Open-metadata Openmetadata < 1.11.4 - Remote Code Execution

Title source: rule
STIX 2.1

Description

OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerability. Version 1.11.4 contains a patch.

Scores

CVSS v3 7.2
EPSS 0.0048
EPSS Percentile 65.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-1336 CWE-94
Status published
Products (2)
open-metadata/openmetadata < 1.11.4
org.open-metadata/platform 0 - 1.11.4Maven
Published Jan 08, 2026
Tracked Since Feb 18, 2026