OmniRoute Vulnerability Leads to Remote Code Execution Risk
Article Content
- •CVE-2026-88062 allows remote code execution in OmniRoute versions 3.8.49 and earlier.
- •The vulnerability can be exploited without authentication if 'requireLogin' is disabled.
- •No patch is currently available, and the vulnerability was disclosed on September 10, 2026.
A critical vulnerability (CVE-2026-88062) in OmniRoute's custom ACP agent endpoint allows remote code execution via user-controlled inputs. The flaw is present in versions 3.8.49 and earlier, where the endpoint accepts arbitrary binary and versionCommand values without proper validation. Attackers can exploit this vulnerability when the 'requireLogin' setting is false, or during the initial setup phase of a fresh instance. This allows unauthorized users to execute arbitrary Node.js code on the server, potentially leading to severe security breaches. The vulnerability was disclosed on September 10, 2026, and no fixed version has been released yet. Security professionals are advised to review their configurations to mitigate risks associated with this vulnerability.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-88062 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…