Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

LangBot MCP Server RCE via Insufficient Authorization

LangBot versions 4.10.7 and earlier allow authenticated users to execute arbitrary commands on the server by configuring STDIO MCP servers without proper authorization checks. An attacker with an account can achieve remote code execution with service privileges.

Disclosed 20 August 2026 · Record updated 13 September 2026

Impact

Arbitrary command execution with LangBot service privileges, enabling data disclosure, modification, and service disruption

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54449