What is CVE-2026-18998?
CVE-2026-18998 is an improper authorization vulnerability in the `SubAgent.run` function of the `delegate_task` Tool in cosmicstack-labs mercury-agent up to version 1.1.12. The flaw allows remote attackers to perform unauthorized actions, so users should update the component or review access controls immediately.
Azərbaycanca: CVE-2026-18998 cosmicstack-labs mercury-agent-in 1.1.12 versiyasına qədər olan versiyalarında `delegate_task` alətinin `SubAgent.run` funksiyasında düzgün olmayan avtorizasiya zəifliyidir. Bu zəiflik uzaqdan hücuma imkan verir, ona görə də istifadəçilər dərhal komponenti yeniləməli və ya giriş nəzarətlərini nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: cosmicstack-labs
FAQ2
In which component of mercury-agent does CVE-2026-18998 exist?
The vulnerability exists in the `SubAgent.run` function of the `delegate_task` Tool.
What is recommended to mitigate this Improper Authorization vulnerability?
Users are advised to immediately update the component or review access controls.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.