---
id: CVE-2026-42425
title: >-
  OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows
  authenticated administrative users to execute arbitrary SQL statements against
  the application database via the DatabaseQuery interface
summary: >-
  OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows
  authenticated administrative users to execute arbitrary SQL statements against
  the application database via the DatabaseQuery interface. Attackers can submit
  …
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
published: '2026-05-26'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42425'
references:
  - url: 'https://github.com/terrasystemlabs/Exploits/tree/main/OpenKM-Exploits'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/terrasystemlabs/Exploits/tree/main/OpenKM-Exploits/nuclei-templates/openkm-sql-database-query
    label: disclosure@vulncheck.com
  - url: 'https://hub.docker.com/r/openkm/openkm-ce'
    label: disclosure@vulncheck.com
  - url: >-
      https://terrasystemlabs.com/post?slug=openkm-zero-day-vulnerabilities-terra-system-labs
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/52520'
    label: disclosure@vulncheck.com
  - url: 'https://www.openkm.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openkm-unrestricted-sql-execution-via-databasequery
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00891
epssPercentile: 0.58089
ingestedAt: '2026-10-06T22:23:15.926Z'
---

## Overview

OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements against the application database via the DatabaseQuery interface. Attackers can submit malicious SQL queries through the qs parameter to the /admin/DatabaseQuery endpoint to extract sensitive data including usernames and password hashes from the OKM_USER table, modify permissions, or delete database records.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
