CVE-2023-25826Disclosure(opentsdb / opentsdb)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. This exploit exists due to an incomplete fix that was made when this vulnerability was previously disclosed as CVE-2020-35476. Regex validation that was implemented to restrict allowed input to the query API does not work as intended, allowing crafted commands to bypass validation.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opentsdb

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
opentsdb

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-24: 1PoC Mentioned / Linked · 2026-08-24: 1Technical Details · 2026-08-24: 108-24
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2023-25826 - critical 🚨 OpenTSDB <= 2.4.1 - Unauthenticated RCE via Gnuplot Injection > OpenTSDB contains a command injection caused by insufficient validation of parameters... 👾 https://cloud.projectdiscovery.io/library/CVE-2023-25826 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet discloses CVE‑2023‑25826, highlighting an unauthenticated remote code execution flaw in OpenTSDB <=2.4.1 through Gnuplot injection, and links to further details.

    00040330
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopentsdbopentsdb---

Explore more