Authentication Bypass in Soft Machine's Cloud OS Affects Data Security
CVE-2026-46711

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-46711?

The Cloud OS from Soft Machine, specifically versions 0.2.247 and earlier, has a critical vulnerability in its workspace HTTP service. This service listens on port 8080 and exposes sensitive endpoints without proper authentication or origin checks. As a result, any host capable of reaching TCP/8080 can access arbitrary files within the workspace's root directory. This flaw permits unauthorized users to read sensitive project files and download entire project trees as tar archives. Furthermore, due to a lack of effective trust boundaries, any other sm-ws-* machine operating under the same Fly application or organization could exploit this vulnerability, thereby enhancing the risks associated with data exfiltration. Currently, there are no known patches for this vulnerability.

Affected Version(s)

security <= 0.2.247

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.