CVE-2026-27851
High
Published: 12 May 2026
Published
12 May 2026
Modified
12 May 2026
KEV Added
—
Patch
—
CVSS Score
7.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
N/A
Risk Priority
15
60% EPSS · 20% KEV · 20% CVSS
Summary
CVE-2026-27851 is a high-severity Improper Handling of Extra Parameters (CWE-235) vulnerability in Open Xchange (inferred from references). Its CVSS base score is 7.4 (High).
Operationally, it is not currently listed in the CISA KEV catalog.
NVD Description
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid…
more
using safe filter until on fixed version. No publicly available exploits are known.
Deeper analysisAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)
Affected Products
Open Xchange
—
inferred from references and description; NVD did not file a CPE for this CVE