CVE-2026-52102
CRITICALOpenMediaVault 8.0.4-1 - OS Command Injection via openmediavault-md Plugin Shell Metacharacter Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-52102. PoCs published by showmeyourhands.
AI-analyzed exploit summary This PoC exploits an authenticated command injection vulnerability (CVE-2026-52102) in OpenMediaVault's RPC interface. The exploit chains credential brute-forcing with a semicolon-injected command in the 'devices' parameter of the 'MdMgmt.create' method to achieve remote code execution.
Description
An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.
Exploits (1)
This PoC exploits an authenticated command injection vulnerability (CVE-2026-52102) in OpenMediaVault's RPC interface. The exploit chains credential brute-forcing with a semicolon-injected command in the 'devices' parameter of the 'MdMgmt.create' method to achieve remote code execution.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H