CVE-2026-26002
OnDemand susceptible to malicious input when navigating to a directory.
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when navigating to a directory. This has been patched in versions 4.0.9 and 4.1.3. Versions below this remain susceptible.
| CWE | CWE-74 |
| Vendor | osc |
| Product | ondemand |
| Published | Mar 4, 2026 |
| Last Updated | Mar 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for osc ondemand
Be the first to know when new unknown vulnerabilities affecting osc ondemand are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
OSC / ondemand
< 4.0.9 >= 4.1.0, < 4.1.3