Authentication Bypass in DeepSeek Harness by DeepSeek
CVE-2026-82533
Key Information:
- Vendor
Deepseek
- Status
- Vendor
- CVE Published:
- 8 September 2026
Badges
What is CVE-2026-82533?
CVE-2026-82533 is a significant security vulnerability found in DeepSeek Harness, a software product developed by Deepseek for managing various computational tasks. The vulnerability exists within the local HTTP control-plane API of DeepSeek Harness versions prior to 0.1.2-alpha.1 and is classified as an authentication bypass issue. This flaw arises because the server relies solely on the client-supplied Host header for authentication, rather than verifying the true origin of the TCP connection. As a result, attackers can exploit this weakness by crafting a malicious request with a spoofed Host header, allowing them to gain full control over connected agents without valid credentials or API keys. Such control can enable them to execute privileged commands, escalate session approvals, and access all stored conversations, posing a grave risk to the integrity and confidentiality of the organization's data.
Potential impact of CVE-2026-82533
-
Unauthorized Access and Control: The exploitation of this vulnerability permits attackers to attain complete agent control, allowing them to perform administrative tasks that could compromise the entire system and its data.
-
Data Breaches: With the ability to execute commands and retrieve stored conversations without proper authorization, organizations could face significant data breaches, leading to potential loss of sensitive information and trust from clients and stakeholders.
-
Malicious Commands Execution: Attackers can utilize this vulnerability to invoke high-level commands with extensive permissions. This capability not only endangers the immediate environment but can also facilitate the deployment of further attacks, including the execution of malicious scripts or installation of malware within the organization's network.
Affected Version(s)
DeepSeek Harness 0 < 0.1.2-alpha.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
