Unauthenticated Access in Ruflo Agent Meta-Harness
CVE-2026-59726
Key Information:
Badges
What is CVE-2026-59726?
The Ruflo Agent Meta-Harness prior to version 3.16.3 had a critical security flaw wherein its default Docker deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without any authentication. This oversight potentially allowed an unauthenticated attacker to execute commands, gaining unauthorized access to critical functionalities such as tools/call to terminal_execute. This could lead to obtaining sensitive information like provider API keys and manipulating AgentDB learning-store patterns. Users are advised to upgrade to version 3.16.3 or later to mitigate this risk.
Affected Version(s)
ruflo < 3.16.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Ruflo CVE-2026-59726 exposes an unauthenticated MCP bridge that could enable RCE, LLM key theft, conversation access, and AI memory poisoning.
1 day ago
Patch-Resistant Ruflo Flaw Can Unleash Malicious AI Agent Swarms
The flaw in the AI hosting platform Ruflo allows an unauthenticated attacker to take over and corrupt memory, so bad behavior persists after patching.
1 day ago
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
- π°
First article discovered by Dark Reading
Vulnerability published
Vulnerability Reserved
