What is CVE-2026-72776?
A critical unauthenticated remote code execution (RCE) vulnerability has been identified in AgenticSeek (commit fc242c7), exposing the unprotected POST /query API endpoint on 0.0.0.0:7777 with wildcard CORS. Any network-adjacent attacker can exploit this flaw by sending crafted queries to execute arbitrary commands on the system. Immediate isolation of the endpoint and implementation of authentication are strongly recommended.
Azərbaycanca: AgenticSeek platformasının fc242c7 commit versiyasında autentifikasiya tələb etməyən uzaqdan kod icrası (Remote Code Execution) zəifliyi aşkarlanıb. Bu boşluq şəbəkəyə qoşulu hər hansı bir hücumçuya xüsusi hazırlanmış sorğuları 0.0.0.0:7777 ünvanındakı POST /query API endpointinə göndərərək sistemdə özbaşına əmrlər icra etməyə imkan verir. Təcili olaraq bu endpoint-i şəbəkədən təcrid etmək və autentifikasiya mexanizmi əlavə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Does exploiting CVE-2026-72776 in the AgenticSeek platform require authentication?
No, CVE-2026-72776 is an unauthenticated remote code execution (RCE) vulnerability. Any network-adjacent attacker can exploit this flaw without any authentication.
Which API endpoint must an attacker target to exploit CVE-2026-72776?
An attacker must send crafted queries to the POST /query API endpoint at 0.0.0.0:7777. This endpoint has been left unprotected and exposed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.