Vulnerability threat dossier

CVE-2022-26833

openautomationsoftwareoas platform

An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to trigger this vulnerability.

VTP deterministic threat7.5of 100 · CVSS excluded

VTP analyst assessment

OAS Platform REST API authentication bypass

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence72%
Public exploitation · VTP factUNKNOWN

Assessment

Open Automation Software OAS Platform V16.00.0121 has an improper-authentication flaw in its REST API that can be triggered through a crafted sequence of HTTP requests, enabling unauthenticated API use. The supplied CVSS is 9.4, with high integrity and availability impact. No exploitation evidence is supplied.

Why it matters

  • Unauthenticated REST API use could permit consequential changes or service disruption.
  • The supplied attack vector is remote, low complexity, and requires no user interaction.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The affected-product CPE identifies 16.00.0112 while the description names V16.00.0121, creating a version-scope inconsistency.

Only one reference is counted, with no source text, KEV entry, assertions, or first-party telemetry supplied.

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

Next watchpoint

Resolve the 16.00.0112 versus 16.00.0121 version discrepancy before scoping exposure.

AI baseline history (1)
  1. BASELINE ASSESSED
    OAS Platform REST API authentication bypassgpt-5.6-sol · high
Technical severityCRITICALCVSS 9.4 · technical context
Public exploitationUNKNOWNGlobal public evidence
Exploit maturityNONE KNOWNReliability not implied
EPSS0.3898th percentile · prediction
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
MEDIUM

Honeypot request semantics are potentially consistent with CVE-2022-26833. The match tolerates bounded payload variants and remains unconfirmed.

POTENTIALLY COMPATIBLETechnical consistency 80/100

Basis: deterministic technical candidate

Potentially consistent; exploitation not confirmedDisclosure embargo completed
MEDIUM

Honeypot request semantics are potentially consistent with CVE-2022-26833. The match tolerates bounded payload variants and remains unconfirmed.

POTENTIALLY COMPATIBLETechnical consistency 80/100

Basis: deterministic technical candidate

Potentially consistent; exploitation not confirmedDisclosure embargo completed
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.38; this is predictive context, not exploitation evidence.

  2. 02

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

0publications detected
0underlying evidence chains

0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

04

Event history

Threat timeline

    05

    Original publications

    Source record

    06

    Technical vulnerability data

    Context, not threat proof

    VTP threat score7.5vtp-threat-v1-public
    Public exploitation0 / 30
    EPSS prediction7.53 / 20
    Exploit availability0 / 15
    Source independence0 / 15
    Intelligence recency0 / 10
    Threat acceleration0 / 10
    CVSS technical severityExcluded
    CVSS
    9.4 · CRITICAL
    Vector
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
    CWE
    CWE-306
    CPE records
    1
    Deterministic history records
    20
    Primary technical reference
    07

    Raw observations

    First-party sensor records

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.