Skip to content
OmniRoute Vulnerability Leads to Remote Code Execution Risk

OmniRoute Vulnerability Leads to Remote Code Execution Risk

First seen 11 Sep 2026, 07:16 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 20:35 UTC
  • CVE-2026-88062 allows remote code execution in OmniRoute versions 3.8.49 and earlier.
  • The vulnerability can be exploited without authentication if 'requireLogin' is disabled.
  • No patch is currently available, and the vulnerability was disclosed on September 10, 2026.

A critical vulnerability (CVE-2026-88062) in OmniRoute's custom ACP agent endpoint allows remote code execution via user-controlled inputs. The flaw is present in versions 3.8.49 and earlier, where the endpoint accepts arbitrary binary and versionCommand values without proper validation. Attackers can exploit this vulnerability when the 'requireLogin' setting is false, or during the initial setup phase of a fresh instance. This allows unauthorized users to execute arbitrary Node.js code on the server, potentially leading to severe security breaches. The vulnerability was disclosed on September 10, 2026, and no fixed version has been released yet. Security professionals are advised to review their configurations to mitigate risks associated with this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-10
CVE-2026-88062 published
OmniRoute's vulnerability allows remote code execution via user-controlled inputs in the ACP agent endpoint.
Cve
2026-09-10
OmniRoute vulnerability disclosed
Security researchers revealed the flaw, highlighting the lack of proper validation in the affected endpoint.
Github
2026-09-11
Security advisories published
Multiple advisories were released, warning users about the critical nature of CVE-2026-88062.
Advisories.Gitlab

More articles in this cluster (5)

Following this threat?

Track CVE-2026-88062 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed