← Vulnerability feed

Vulnerability record · CVE-2013-3632 · published 29 September 2014

CVE-2013-3632: OpenMediaVault rpc.php cron service allows arbitrary command execution

Openmediavault · Openmediavault

The Cron service in rpc.php in OpenMediaVault fails to properly restrict the username parameter, letting a remote authenticated user schedule cron jobs as arbitrary users and run arbitrary commands. Because the flaw grants command execution with the privileges of any chosen account, it undermines the separation between low-privileged users and the system.

8.8 CVSS 3.1 High EPSS 57% · top 1.0% CWE-264 · Permissions and access controls
8.8CVSS 3.1 base score, v2 9.0
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
11References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityRemote authenticated command execution with high confidentiality, integrity and availability impact, plus public exploit code and very high EPSS, though it requires valid credentials and is not in KEV.

What it is

The Cron service in rpc.php in OpenMediaVault fails to properly restrict the username parameter, letting a remote authenticated user schedule cron jobs as arbitrary users and run arbitrary commands. Because the flaw grants command execution with the privileges of any chosen account, it undermines the separation between low-privileged users and the system.

Impact

An attacker with a valid account gains arbitrary command execution as other users, including potentially root, leading to full compromise of the OpenMediaVault host and its managed storage.

Attack surface

Reached over the network through rpc.php; the CVSS vector (AV:N/PR:L/UI:N) indicates a valid low-privileged account is required and no user interaction is needed.

Exploitation

Public exploit code exists (Exploit-DB 29323 and Metasploit-related references), and EPSS is 0.571 (99th percentile), though the CVE is not listed in CISA KEV.

What to do

  • Apply the OpenMediaVault update that fixes the rpc.php cron handling; if no patch is available for your release, upgrade to a supported version.
  • Restrict network access to rpc.php and the OpenMediaVault web interface to trusted management networks.
  • Audit and minimize accounts with access to the OpenMediaVault interface, and remove unused accounts.
  • Review cron jobs and system users for unauthorized entries created via the cron service.

Detection

  • Monitor rpc.php requests for cron-related actions with unexpected or privileged username values.
  • Alert on new or modified cron entries, especially those running as root or other privileged users.
  • Correlate OpenMediaVault authentication logs with subsequent cron job creation and command execution events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-3632 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-26124OpenMediaVault rpc.php sortfield PHP code injectionOpenMediaVault before 4.1.36 and 5.x before 5.5.12 fails to use json_encode_safe in config/databasebackend.inc, allowing PHP code injection through t…EPSS 67%analysed7.8CVE-2025-50674Openmediavault improper input validation vulnerabilityAn issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowing local au…EPSS 0.19%6.1CVE-2017-1000065Openmediavault cross-site scripting vulnerabilityMultiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows …EPSS 0.74%5.1CVE-2015-3246libuser userhelper direct /etc/passwd write race conditionlibuser before 0.56.13-8 and 0.60 before 0.60-7, as used by the userhelper program in the usermode package, modifies /etc/passwd directly instead of …KEVEPSS 8.8%analysed6.6CVE-2015-1769Windows Mount Manager symlink mishandling allows local privilege escalationThe Windows Mount Manager mishandles symbolic links, allowing a crafted USB device to trigger arbitrary code execution. Because the flaw is in a core…KEVEPSS 4.1%analysed7.8CVE-2016-3643SolarWinds Virtualization Manager sudo misconfiguration privilege escalationSolarWinds Virtualization Manager 6.3.1 and earlier ship with a misconfigured sudo policy that lets a local user run privileged commands, as shown by…KEVEPSS 3.7%analysed

Source: NIST National Vulnerability Database (record CVE-2013-3632), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.