PatchSiren

OpenMediaVault CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL OpenMediaVault CVE published 2026-08-03

CVE-2026-52102

The openmediavault-md plugin of OpenMediaVault v8.0.4-1 is vulnerable to OS command injection, allowing attackers to execute arbitrary commands as root via injecting shell metacharacters. This critical vulnerability has a CVSS score of 9.8. Affected product context indicates OpenMediaVault installations with the openmediavault-md plugin are impacted. The CVE record was published on 2026-08-03T21:16:40.273 [truncated]