Vulnerability Description
A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/application/websockets/share.py of the component ShareServer WebSocket Endpoint. Performing a manipulation of the argument interaction_id results in missing authentication. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openbmb | Xagent | 1.0.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/YLChen-007/531ec6b169f4b9ecbc8c2f0b2cd7c5eeExploitThird Party Advisory
- https://vuldb.com/?ctiid.353836Permissions RequiredVDB Entry
- https://vuldb.com/?id.353836Permissions RequiredVDB Entry
- https://vuldb.com/?submit.777622Issue TrackingThird Party Advisory
FAQ
What is CVE-2026-4959?
CVE-2026-4959 is a vulnerability with a CVSS score of 7.3 (HIGH). A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/application/websockets/share.py of the component ShareServer WebSocket Endpoint. Perfor...
How severe is CVE-2026-4959?
CVE-2026-4959 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-4959?
Check the references section above for vendor advisories and patch information. Affected products include: Openbmb Xagent.