OmniRoute RCE via unauthenticated POST /api/acp/agents endpoint
OmniRoute versions 3.8.49 and earlier allowed remote code execution through the POST /api/acp/agents endpoint by passing attacker-controlled binary and versionCommand values that bypassed security filters. An unauthenticated attacker could execute arbitrary code on the server when requireLogin was false or during bootstrap.
Disclosed 10 September 2026 · Record updated 13 September 2026
Impact
Remote code execution in server container accessible to anonymous attackers when requireLogin=false or during bootstrap window
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-88062
