{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/omniroute/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:omniroute:omniroute:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-88062"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OmniRoute (\u003c= 3.8.50)"],"_cs_severities":["critical"],"_cs_tags":["rce","cve-2026-88062","omniroute"],"_cs_type":"advisory","_cs_vendors":["OmniRoute"],"content_html":"\u003cp\u003eOmniRoute version 3.8.50 and earlier are affected by a critical remote code execution (RCE) vulnerability (CVE-2026-88062) within the \u003ccode\u003e/api/acp/agents\u003c/code\u003e endpoint. The vulnerability exists because the application accepts user-controlled \u003ccode\u003ebinary\u003c/code\u003e and \u003ccode\u003eversionCommand\u003c/code\u003e parameters to register custom ACP agents. The application fails to properly validate the \u003ccode\u003eversionCommand\u003c/code\u003e argument, allowing an attacker to inject arbitrary JavaScript code that is executed by the server via \u003ccode\u003echild_process.execFileSync\u003c/code\u003e during a version probe.\u003c/p\u003e\n\u003cp\u003eThis endpoint is reachable by anonymous users if the instance has \u003ccode\u003erequireLogin=false\u003c/code\u003e or during the initial bootstrap phase before a management password is set. Because the endpoint lacks necessary restrictions defined in the \u003ccode\u003eLOCAL_ONLY_API_PREFIXES\u003c/code\u003e or \u003ccode\u003eSPAWN_CAPABLE_PREFIXES\u003c/code\u003e policies, the request bypasses authorization checks. An attacker can use this vulnerability to achieve full command execution within the context of the OmniRoute server container.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target OmniRoute instance where \u003ccode\u003erequireLogin\u003c/code\u003e is set to \u003ccode\u003efalse\u003c/code\u003e, or targets a new instance during its initial setup window.\u003c/li\u003e\n\u003cli\u003eAttacker sends an unauthenticated \u003ccode\u003ePOST\u003c/code\u003e request to the \u003ccode\u003e/api/acp/agents\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe request body contains malicious \u003ccode\u003ebinary\u003c/code\u003e (e.g., \u0026quot;node\u0026quot;) and \u003ccode\u003eversionCommand\u003c/code\u003e fields, where the latter includes an \u003ccode\u003e-e\u003c/code\u003e argument followed by arbitrary JavaScript code.\u003c/li\u003e\n\u003cli\u003eThe OmniRoute application saves the agent definition without verifying the safety of the \u003ccode\u003eversionCommand\u003c/code\u003e content beyond a simple token consistency check.\u003c/li\u003e\n\u003cli\u003eThe application automatically triggers \u003ccode\u003erefreshAgentCache()\u003c/code\u003e, which invokes \u003ccode\u003edetectInstalledAgents()\u003c/code\u003e to probe the new agent.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003edetectAgent()\u003c/code\u003e function calls \u003ccode\u003eexecFileSync\u003c/code\u003e to execute the attacker-provided \u003ccode\u003eversionCommand\u003c/code\u003e string.\u003c/li\u003e\n\u003cli\u003eThe Node.js process executes the injected JavaScript, allowing the attacker to interact with the underlying OS via \u003ccode\u003echild_process.execSync()\u003c/code\u003e.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthenticated remote code execution within the OmniRoute server container. This grants an attacker the ability to execute system commands, access environment variables, manipulate local data files (such as database backups or configuration files), and potentially move laterally within the containerized environment. This vulnerability affects all OmniRoute instances running versions 3.8.50 and earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade all OmniRoute instances to a version later than 3.8.50.\u003c/li\u003e\n\u003cli\u003eEnable \u003ccode\u003erequireLogin=true\u003c/code\u003e and enforce strong management authentication to prevent unauthenticated access to administrative API endpoints.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules below to monitor for unauthorized requests to the ACP agent registration endpoint.\u003c/li\u003e\n\u003cli\u003eMonitor webserver logs for \u003ccode\u003ePOST\u003c/code\u003e requests to \u003ccode\u003e/api/acp/agents\u003c/code\u003e originating from external or untrusted network segments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-11T18:56:20Z","date_published":"2026-09-11T18:56:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-omniroute-rce/","summary":"OmniRoute contains a critical remote code execution vulnerability (CVE-2026-88062) in the /api/acp/agents endpoint, allowing anonymous attackers to execute arbitrary code when requireLogin is disabled.","title":"Unauthenticated Remote Code Execution in OmniRoute ACP","url":"https://feed.craftedsignal.io/briefs/2026-09-omniroute-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Omniroute","version":"https://jsonfeed.org/version/1.1"}