CVE-2026-62674 is an authorization-boundary flaw in Omnigent before 0.3.0. The session agent-update functionality validated that the requester held LEVEL_EDIT permission for a session but did not reject a bound shared or template agent identified by a null session ownership value. Consequently, a user authorized to edit one session could overwrite a global shared agent bundle. An attacker could add a stdio MCP server configuration to the modified bundle; when a later session used that shared agent, Omnigent could launch an attacker-controlled command through its MCP tooling. The defect is classified as CWE-94.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical arbitrary-code-execution vulnerability in Omnigent's session-agent bundle update endpoint. An authenticated low-privilege user could modify a global built-in agent template and supply malicious MCP server configuration, causing commands to execute in the Omnigent runner context. This could expose environment credentials, permit repository and pipeline tampering, enable lateral movement within container networks, and potentially facilitate host or cloud-metadata compromise where isolation is weak.
An authenticated remote code execution vulnerability in Omnigent versions before 0.3.0. The full agent-bundle upload endpoint permits a user who can edit their own session to overwrite a shared/template agent because it lacks the shared-agent read-only guard. An attacker can add a stdio MCP server whose configured command subsequently executes as a local subprocess with the Omnigent runner process's privileges.
An authenticated remote code execution vulnerability in Omnigent caused by improper validation of shared/template agent binding, allowing a user with session edit access to overwrite a shared agent bundle and trigger attacker-controlled command execution in the runner process.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.