Unauthenticated Access in Ruflo Agent Meta-Harness
CVE-2026-59726

10CRITICAL

Key Information:

Vendor

Ruvnet

Status
Vendor
CVE Published:
9 July 2026

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoCπŸ“° News Worthy

What is CVE-2026-59726?

The Ruflo Agent Meta-Harness prior to version 3.16.3 had a critical security flaw wherein its default Docker deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without any authentication. This oversight potentially allowed an unauthenticated attacker to execute commands, gaining unauthorized access to critical functionalities such as tools/call to terminal_execute. This could lead to obtaining sensitive information like provider API keys and manipulating AgentDB learning-store patterns. Users are advised to upgrade to version 3.16.3 or later to mitigate this risk.

Affected Version(s)

ruflo < 3.16.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Ruflo CVE-2026-59726 exposes an unauthenticated MCP bridge that could enable RCE, LLM key theft, conversation access, and AI memory poisoning.

1 day ago

Patch-Resistant Ruflo Flaw Can Unleash Malicious AI Agent Swarms

The flaw in the AI hosting platform Ruflo allows an unauthenticated attacker to take over and corrupt memory, so bad behavior persists after patching.

1 day ago

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by Dark Reading

  • Vulnerability published

  • Vulnerability Reserved

.