Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

OmniRoute RCE via unauthenticated POST /api/acp/agents endpoint

OmniRoute versions 3.8.49 and earlier allowed remote code execution through the POST /api/acp/agents endpoint by passing attacker-controlled binary and versionCommand values that bypassed security filters. An unauthenticated attacker could execute arbitrary code on the server when requireLogin was false or during bootstrap.

Disclosed 10 September 2026 · Record updated 13 September 2026

Impact

Remote code execution in server container accessible to anonymous attackers when requireLogin=false or during bootstrap window

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-88062