CVE-2026-88062 | diegosouzapw OmniRoute up to 3.8.49 ACP Agent /api/acp/agents tokenizeVersionCommand versionCommand os command injection

SecurityVulns

A vulnerability, which was classified as critical, was found in diegosouzapw OmniRoute up to 3.8.49. This issue affects the function tokenizeVersionCommand of the file /api/acp/agents of the component ACP Agent. Executing a manipulation of the argument versionCommand can lead to os command injection.

This vulnerability appears as CVE-2026-88062. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More