Authentication Bypass in Soft Machine's Cloud OS Affects Data Security
CVE-2026-46711
What is CVE-2026-46711?
The Cloud OS from Soft Machine, specifically versions 0.2.247 and earlier, has a critical vulnerability in its workspace HTTP service. This service listens on port 8080 and exposes sensitive endpoints without proper authentication or origin checks. As a result, any host capable of reaching TCP/8080 can access arbitrary files within the workspace's root directory. This flaw permits unauthorized users to read sensitive project files and download entire project trees as tar archives. Furthermore, due to a lack of effective trust boundaries, any other sm-ws-* machine operating under the same Fly application or organization could exploit this vulnerability, thereby enhancing the risks associated with data exfiltration. Currently, there are no known patches for this vulnerability.
Affected Version(s)
security <= 0.2.247
