S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 15, 2026

CVE-2026-88062 Scanner

CVE-2026-88062 Scanner - Remote Code Execution (RCE) vulnerability in OmniRoute

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
9.5
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand values and used only a self-consistency check before execFileSync executed the selected interpreter and arguments. The same request called refreshAgentCache, and resolveVersionProbe accepted the matched command before the execFileSync sink ran it. The tokenizeVersionCommand function and DISALLOWED_VERSION_COMMAND_CHARS filter rejected a limited set of shell metacharacters but still allowed interpreter evaluation arguments. The isAuthenticated function relied on isAuthRequired, which accepted anonymous requests when requireLogin was false, while api/acp/ was absent from LOCAL_ONLY_API_PREFIXES and SPAWN_CAPABLE_PREFIXES. With requireLogin=false or during a fresh-instance bootstrap window, a remote anonymous request could supply an interpreter evaluation argument and execute arbitrary code in the server container. With requireLogin=true and a configured management password, exploitation instead required a management session or management-scoped API key. No fixed version is available as of this review.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
OmniRouteby diegosouzapw
< 3.8.49
Updated Sep 18, 2026View on NVD →
Detail

OmniRoute is a comprehensive routing management software used by enterprises to efficiently manage network routes and resources. It enables network administrators to define, optimize, and manage routing policies across various environments. OmniRoute is used to ensure seamless data flow and connectivity in both on-premises and cloud-based systems. The software integrates with various network appliances and supports automation for improved network efficiency. It is widely utilized in industries requiring robust network infrastructure management, including telecommunications and large corporate IT departments. The platform also offers an intuitive interface and extensive API support for custom integrations and automated workflows.

The Remote Code Execution (RCE) vulnerability detected in OmniRoute poses a significant security risk. This vulnerability allows an attacker to execute arbitrary code on the target system without authentication. The issue stems from insufficient validation of interpreter arguments in the POST /api/acp/agents endpoint. Exploiting this flaw requires anonymous access when the requireLogin parameter is set to false, or access through a valid management session or API key when set to true. Successfully exploiting this vulnerability can lead to a complete system compromise, highlighting the critical nature of the issue.

Technically, the vulnerability details reveal that the POST /api/acp/agents endpoint is vulnerable. Attackers can exploit this endpoint by sending specially crafted JSON payloads. The payload exploits the insufficient validation process, allowing the execution of arbitrary commands through the 'node' binary execution. Key parameters like 'versionCommand' allow attacker-controlled code execution, exemplified by the invocation of system commands that output sensitive file contents. Attackers achieving a successful response find the 'root' pattern in the returned data, indicating privileged access was improperly granted.

Exploiting this vulnerability can lead to severe consequences, including unauthorized access to sensitive data, system alteration, or a complete system takeover. The arbitrary code execution facilitates data breaches, data loss, and unauthorized network alterations. This impact can impede organizational operations, damage reputation, and incur legal liabilities. Organizations failing to mitigate this risk may face prolonged operational downtimes and expose sensitive client data to malicious entities.

REFERENCES

Solution Advice
  • Update to the latest patched version of OmniRoute as soon as the fix becomes available.
  • Enable strict access controls and authentication mechanisms to the POST /api/acp/agents endpoint.
  • Regularly monitor and audit network systems for unauthorized access or anomalies.
  • Implement network segmentation to limit the impact of potential exploits.
  • Ensure all security patches and updates are applied promptly to mitigate known vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.