MEDIUM🇵🇱 Wersja polska

CVE-2026-4959

CVSS 5.5v4.0pub. 2026-03-27upd. 2026-04-29

A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/application/websockets/share.py of the component ShareServer WebSocket Endpoint. Performing a manipulation of the argument interaction_id results in missing authentication. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Openbmb Xagent

    APP
    Openbmb
    1.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-2007MEDIUM5.3same product

A vulnerability was found in OpenBMB XAgent 1.0.0. It has been declared as critical. Affected by this vulnerab...

CVE-2026-4957LOW2.0same product

W OpenBMB XAgent 1.0.0 znaleziono lukę. Problem dotyczy funkcji FunctionHandler.handle_tool_call w pliku XAgen...

CVE-2026-4958LOW1.3same product

Odkryta została podatność w OpenBMB XAgent 1.0.0 w funkcjach ReplayServer.on_connect/ReplayServer.send_data pl...

CVE-2025-6281LOW2.0same product

W OpenBMB XAgent do wersji 1.0.0 odkryto krytyczną lukę bezpieczeństwa dotyczącą nieznanej funkcjonalności pli...