CVE-2026-72776: Missing Authentication for Critical Function in Fosowl AgenticSeek
AgenticSeek contains a critical unauthenticated remote code execution vulnerability via its unprotected POST /query API endpoint. This endpoint listens on all interfaces (0.0.0.0:7777) with wildcard CORS, allowing any network-adjacent attacker to send crafted queries. The vulnerability enables attackers to execute arbitrary shell commands through the BashInterpreter using subprocess.Popen with unsafe parameters, bypassing command blocklists and achieving full host-level code execution.
AI Analysis
Technical Summary
CVE-2026-72776 affects Fosowl's AgenticSeek (commit fc242c7) and involves a missing authentication mechanism on the POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS enabled. Attackers can submit unauthenticated HTTP requests that cause the autonomous agent to generate and execute arbitrary shell commands via BashInterpreter. The subprocess.Popen call uses shell=True and safety=False, allowing bypass of the incomplete command blocklist and resulting in full remote code execution on the host.
Potential Impact
An unauthenticated attacker with network access to the affected service can execute arbitrary commands on the host system, leading to full host-level compromise. This can result in complete control over the affected system, data breach, service disruption, or further lateral movement within the network.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict network access to the POST /query endpoint and disable or limit the use of the BashInterpreter subprocess execution functionality if possible.
CVE-2026-72776: Missing Authentication for Critical Function in Fosowl AgenticSeek
Description
AgenticSeek contains a critical unauthenticated remote code execution vulnerability via its unprotected POST /query API endpoint. This endpoint listens on all interfaces (0.0.0.0:7777) with wildcard CORS, allowing any network-adjacent attacker to send crafted queries. The vulnerability enables attackers to execute arbitrary shell commands through the BashInterpreter using subprocess.Popen with unsafe parameters, bypassing command blocklists and achieving full host-level code execution.
CVSS v4.0
Score 9.3critical
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-72776 affects Fosowl's AgenticSeek (commit fc242c7) and involves a missing authentication mechanism on the POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS enabled. Attackers can submit unauthenticated HTTP requests that cause the autonomous agent to generate and execute arbitrary shell commands via BashInterpreter. The subprocess.Popen call uses shell=True and safety=False, allowing bypass of the incomplete command blocklist and resulting in full remote code execution on the host.
Potential Impact
An unauthenticated attacker with network access to the affected service can execute arbitrary commands on the host system, leading to full host-level compromise. This can result in complete control over the affected system, data breach, service disruption, or further lateral movement within the network.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict network access to the POST /query endpoint and disable or limit the use of the BashInterpreter subprocess execution functionality if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-10T15:09:12.955Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7e3a17bf8831d539d7042e
Added to database: 08/13/2026, 21:41:43 UTC
Last enriched: 08/13/2026, 21:56:47 UTC
Last updated: 08/14/2026, 00:24:33 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.