A critical vulnerability tracked as CVE-2026-59801 affects 9Router through version 0.4.41, exposing provider management functions through the /api/providers API without authentication. The flaw stems from missing authentication middleware in Next.js routes under src/app/api/providers/*, allowing remote attackers to reach sensitive endpoints with no credentials. The issue has been rated 9.8 CVSS v3.1 and classified as CWE-306: Missing Authentication for Critical Function.
Attackers can use the exposed API to enumerate, create, modify, or delete provider connections, potentially revealing partial credentials, OAuth tokens, and API keys. The access could also let an attacker redirect AI traffic to attacker-controlled servers or trigger a denial of service by deleting all provider connections. Reported mitigation is to add authentication middleware and enforce access controls across the affected API routes and endpoints.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
A critical unauthenticated access vulnerability affecting 9Router through version 0.4.41 was publicly disclosed as CVE-2026-59801. The flaw stems from missing authentication middleware on /api/providers routes, enabling remote access to provider management functions and possible exposure or manipulation of credentials and connections.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcecvefeed.io
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.