A critical vulnerability, CVE-2026-88062 with a CVSS score of 9.5, exists in OmniRoute ACP Custom-Agent that allows remote code execution via user-controlled binary and versionCommand fields, which are not properly validated, leading to arbitrary Node.js code execution inside the server container. The vulnerability can be exploited by sending a malicious POST request with crafted binary and versionCommand values, resulting in significant business impact as an attacker can execute OS commands via child_process.execSync. This flaw type is a CWE-94 (Improper Control of Generation of Code) and CWE-306 (Missing Authentication for Critical Data or Function). The attack vector is Network (AV:N), with Attack Complexity set to Low (AC:L), Privileges Required set to None (PR:N), User Interaction set to None (UI:N), and Vector Configuration set to High (VC:H), Vulnerability Impact set to High (VI:H), and Confidentiality, Integrity, and Availability set to High (VA:H/SC:H/SI:H). The vulnerability can be exploited in scenarios where the target instance has requireLogin=false or a fresh instance with no management password configured yet. If the instance is in the default requireLogin=true state and already has a management password, exploitation requires a valid management session or management-scoped API key. Affected versions include omniroute <= 3.8.50.
The following reports contain further technical details:[/subscribe_to_unlock_form]
A critical vulnerability, CVE-2026-88062 with a CVSS score of 9.5, exists in OmniRoute ACP Custom-Agent that allows remote code execution via user-controlled binary and versionCommand fields, which are not properly validated, leading to arbitrary Node.js code execution inside the server container. The vulnerability can be exploited by sending a malicious POST request with crafted binary and versionCommand values, resulting in significant business impact as an attacker can execute OS commands via child_process.execSync. This flaw type is a CWE-94 (Improper Control of Generation of Code) and CWE-306 (Missing Authentication for Critical Data or Function). The attack vector is Network (AV:N), with Attack Complexity set to Low (AC:L), Privileges Required set to None (PR:N), User Interaction set to None (UI:N), and Vector Configuration set to High (VC:H), Vulnerability Impact set to High (VI:H), and Confidentiality, Integrity, and Availability set to High (VA:H/SC:H/SI:H). The vulnerability can be exploited in scenarios where the target instance has requireLogin=false or a fresh instance with no management password configured yet. If the instance is in the default requireLogin=true state and already has a management password, exploitation requires a valid management session or management-scoped API key. Affected versions include omniroute <= 3.8.50.
The following reports contain further technical details:[emaillocker id="1283"]
[/emaillocker]