Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
Published: 2021-09-17
Agents installed by default on Azure Linux virtual machines are vulnerable to a remote code execution flaw that can be exploited with a single request.
https://www.wiz.io/blog/secret-agent-exposes-azure-customers-to-unauthorized-code-execution
https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure
Published: 2021-09-15
Updated: 2026-08-10
Named Vulnerability: OMIGODKnown Exploited Vulnerability (KEV)
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99933