PT-2026-51533 · Unknown · Openharness Ohmo Gateway

·

CVE-2026-56695

·

Published

2026-06-23

·

Updated

2026-09-10

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenHarness ohmo gateway (affected versions not specified)
Description The /resume and /summary slash commands in the gateway default the remote invocable property to True. This allows admitted remote senders to enumerate and load arbitrary session snapshots by ID. An attacker can use this to access victim snapshots through shared gateway channels, potentially exposing private prompts, credentials, tool output, and file paths.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56695
GHSA-399C-3GM2-P29V
PYSEC-2026-3881

Affected Products

Openharness Ohmo Gateway