logo

OPA for Windows Vulnerability Exposes NTLM Hashes

ID: a53ecdca-d071-5c72-95ad-4b81391a36f8

STIX ID: report--a53ecdca-d071-5c72-95ad-4b81391a36f8

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-10-22

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Tenable disclosed CVE-2024-8260 in Open Policy Agent (OPA) for Windows: improper validation permits an attacker to supply an SMB share instead of a Rego file, causing the system to authenticate to an attacker-controlled server and leak Net-NTLMv2 hashes. The leaked credentials could be relayed or cracked for lateral movement and access to other systems; organizations using OPA on Windows should update to v0.68.0 or later to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.