A AegiFlow
HIGHCVSS 8.5EPSS 1.0%

CVE-2026-22244

CVE-2026-22244 updated by NVD

Published
2026-01-07
Modified
2026-09-02
EPSS percentile
61%
Sources
github-advisory, nvd

Summary

OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerability. Version 1.11.4 contains a patch.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.open-metadata:platform1.11.4

Remediation: Upgrade to 1.11.4 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.