What is CVE-2026-73678?
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability. Unauthenticated attackers can execute arbitrary OS commands by sending crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent. Affected systems should be updated to the latest version immediately.
Azərbaycanca: MindsDB Minds Platform-un 26.1.0 və daha əvvəl versiyaları autentifikasiya olmadan uzaqdan kod icrası (Remote Code Execution) zəifliyi ehtiva edir. Mühafizəsiz POST /api/v1/responses/ endpoint-inə xüsusi hazırlanmış sorğular göndərən autentifikasiya olunmamış hücumçular sistemdə ixtiyari OS əmrlərini icra edə bilər. Təsirlənən sistemlərdə proqramı dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which endpoint is exploited in CVE-2026-73678?
The vulnerability is exploited via the unprotected POST /api/v1/responses/ endpoint.
Is authentication required to exploit this vulnerability?
No, an unauthenticated attacker can execute arbitrary OS commands.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.