CVE-2026-52486
Awaiting Analysis Awaiting Analysis - Queue

Denial of Service in OpenDDS via SignedDocument Verification

Vulnerability report for CVE-2026-52486, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: MITRE

Description

An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
opendds opendds From 3.33 (inc) to 3.34 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-52486 is a vulnerability in OpenDDS 3.33.x where a local attacker can cause a denial of service via the verify function in the SIgnedDocument module. The issue stems from improper handling of signed documents, particularly when verifying cryptographic signatures in governance and permissions files signed with OpenSSL's default command.

Detection Guidance

Check if OpenDDS 3.33.x is installed by running: opendds -v or checking package managers like apt or yum. Inspect SignedDocument.cpp in the OpenDDS/dds/DCPS/security/SSL directory for the verify function. Test signed governance or permissions files using openssl cms -verify -inform SMIME to compare OpenDDS verification results.

Impact Analysis

This vulnerability could allow an attacker to disrupt services by causing a denial of service. It may also prevent secure participant creation in DDS-Security due to failed signature verification, even with valid signatures and CA materials. Systems relying on OpenDDS for secure communication could become unavailable or insecure.

Compliance Impact

This vulnerability could impact compliance by failing to enforce secure participant creation and cryptographic verification, potentially violating data integrity and confidentiality requirements in GDPR and HIPAA. Non-compliance may arise if secure communication channels are not maintained due to failed signature verification.

Mitigation Strategies

Upgrade OpenDDS to a patched version if available. Avoid using application/pkcs7-mime signed files; use multipart/signed S/MIME documents instead. Manually verify signed files with openssl cms -verify before loading them into OpenDDS.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-52486. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart