CVE-2026-45779
Open XDMoD SQL Injection Vulnerability Allows Database Compromise.
Halo Surface Signal: 3 out of 5 — possibly public-facing.
A critical SQL injection vulnerability in Open XDMoD, used for analyzing HPC metrics, allows unauthenticated attackers to execute arbitrary SQL commands remotely. This could lead to a complete compromise of the underlying database. All Open XDMoD deployments before version 10.0.3 are affected.