Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-72776: AgenticSeek Unprotected API Allows Code Execution

CVE-2026-72776 · published 21 days ago
Summary

AgenticSeek's API endpoint is accessible to anyone on the network, allowing an attacker to execute arbitrary commands on the system. This could result in unauthorized access to sensitive data or the complete takeover of the system. Update AgenticSeek to the latest version and ensure the API endpoint is properly secured and restricted.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
fosowl agenticseek <= 2.41.1
< f1eb2cfc721f8a21dd16a8b048a9ca89f3259f6f
Original advisory text
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to...
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated HTTP requests that cause the autonomous agent to generate and execute shell commands through BashInterpreter using subprocess.Popen with shell=True and safety=False, bypassing the incomplete command blocklist to achieve full host-level code execution.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published13 Aug 2026
Updated3 Sep 2026
First seen13 Aug 2026
Sources
CVE-2026-72776 · MITRE
Monitor software like this
Free during beta