Media Summary: CVSS 10.0. No authentication required. One malicious packet, and you own the edge device routing the entire WAN. CVE-2026-22812 - OpenCode v1.0.216 - Unauthenticated RCE OX Research found a filename validation bypass that escalates a prior patched authenticated
Cve 2026 42589 Unauthenticated Rce - Detailed Analysis & Overview
CVSS 10.0. No authentication required. One malicious packet, and you own the edge device routing the entire WAN. CVE-2026-22812 - OpenCode v1.0.216 - Unauthenticated RCE OX Research found a filename validation bypass that escalates a prior patched authenticated