CVE-2026-72776: Missing Authentication for Critical Function in Fosowl AgenticSeek
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated HTTP requests that cause the autonomous agent to generate and execute shell commands through BashInterpreter using subprocess.Popen with shell=True and safety=False, bypassing the incomplete command blocklist to achieve full host-level code execution.
AI Analysis
Technical Summary
CVE-2026-72776 is a critical vulnerability in Fosowl's AgenticSeek (commit fc242c7, version 0) where the POST /query API endpoint listens on 0.0.0.0:7777 with wildcard CORS and lacks authentication. Attackers can submit crafted HTTP POST requests that trigger the autonomous agent to generate and execute arbitrary shell commands through BashInterpreter. The subprocess.Popen call uses shell=True and safety=False, and the existing command blocklist is incomplete, enabling attackers to bypass it and achieve remote code execution on the host.
Potential Impact
An unauthenticated remote attacker can execute arbitrary commands on the host running AgenticSeek, resulting in full host-level compromise. The vulnerability requires no privileges or user interaction and is exploitable over the network, making it highly severe.
Mitigation Recommendations
No patch or official fix information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict network access to the POST /query API endpoint and disable or isolate the vulnerable service to prevent exploitation.
CVE-2026-72776: Missing Authentication for Critical Function in Fosowl AgenticSeek
Description
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated HTTP requests that cause the autonomous agent to generate and execute shell commands through BashInterpreter using subprocess.Popen with shell=True and safety=False, bypassing the incomplete command blocklist to achieve full host-level code execution.
CVSS v4.0
Score 9.3critical
Affected software
Fosowl
AgenticSeek
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-72776 is a critical vulnerability in Fosowl's AgenticSeek (commit fc242c7, version 0) where the POST /query API endpoint listens on 0.0.0.0:7777 with wildcard CORS and lacks authentication. Attackers can submit crafted HTTP POST requests that trigger the autonomous agent to generate and execute arbitrary shell commands through BashInterpreter. The subprocess.Popen call uses shell=True and safety=False, and the existing command blocklist is incomplete, enabling attackers to bypass it and achieve remote code execution on the host.
Potential Impact
An unauthenticated remote attacker can execute arbitrary commands on the host running AgenticSeek, resulting in full host-level compromise. The vulnerability requires no privileges or user interaction and is exploitable over the network, making it highly severe.
Mitigation Recommendations
No patch or official fix information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict network access to the POST /query API endpoint and disable or isolate the vulnerable service to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-10T15:09:12.955Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a7e3a17bf8831d539d7042e
Added to database: 08/13/2026, 21:41:43 UTC
Last enriched: 09/25/2026, 02:39:19 UTC
Last updated: 09/26/2026, 13:47:48 UTC
Views: 52
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.