• OpenKM Vulnerabilities

  • OpenKM has many interesting features, but requires some configuration process to show its full potential.
OpenKM has many interesting features, but requires some configuration process to show its full potential.
Forum rules: Please, before asking something see the documentation wiki or use the search feature of the forum. And remember we don't have a crystal ball or mental readers, so if you post about an issue tell us which OpenKM are you using and also the browser and operating system version. For more info read How to Report Bugs Effectively.
 #54970  by skumar12
 
Hello OpenKM community,

We at Terra System Labs have recently completed a comprehensive whitepaper that dives into zero-day vulnerabilities identified in OpenKM - including root cause analysis, exploit mechanics, risk impact, and actionable recommendations for mitigation. The official patch is not available during the writing of this whitepaper.

Why this matters:
📌 OpenKM is widely used for document management - making its security posture critical.
📌 Our research highlights exploitation vectors that could lead to unauthorized access, data leakage, or privilege escalation.
📌 Make the server vulnerable to Ransomware or internal lateral movement.
📌 We offer detailed findings and defensive controls that can help developers, administrators, and security teams strengthen deployments.

What’s inside the whitepaper:
✔ Technical breakdown of each zero-day vulnerability
Proof-of-Concept (PoC) insights
✔ Risk scoring and threat context
✔ Remediation guidance and secure configuration best practices
✔ References to relevant standards and secure coding principles

🔗 Read the full whitepaper here:
https://terrasystemlabs.com/post?slug=o ... ystem-labs

We believe this research will be valuable for anyone building, maintaining, or securing OpenKM installations. Looking forward to your thoughts, feedback, and any additional findings from the community!

Credit: Terra System Labs Security Research Team
Attachments
OpenKM-Exploit.png
OpenKM-Exploit.png (128.84 KiB) Viewed 5616 times
 #54973  by pavila
 
Dear Terra System Labs team,

Thank you for the time and effort you have dedicated to reviewing OpenKM and for sharing your observations with us.

However, we would like to clarify several important points:

The reported functionalities (Database Query and Scripting) are administrative tools intentionally designed for support and troubleshooting purposes. They are not vulnerabilities. These features are comparable to administrative consoles commonly found in most enterprise systems (such as WordPress, Jira, Alfresco, among others).

Their use strictly requires valid administrator credentials as an absolute prerequisite. In such a scenario, an attacker would already possess extensive control over the system. Therefore, classifying these functionalities as a “Critical Zero-Day RCE” does not align with industry-standard CVSS/CVE classification criteria.

As an additional security measure, we have decided to remove these functionalities.

We remain at your disposal should you require any further clarification.

Kind regards,

About Us

OpenKM is part of the management software. A management software is a program that facilitates the accomplishment of administrative tasks. OpenKM is a document management system that allows you to manage business content and workflow in a more efficient way. Document managers guarantee data protection by establishing information security for business content.