logo

CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In

ID: b3396356-88f8-54b1-90bb-b4f6a9b882f8

STIX ID: report--b3396356-88f8-54b1-90bb-b4f6a9b882f8

Feed Name: HackRead

Threat Score
85/100

Date Published: 2026-07-29

Date Updated: 2026-07-29

Author: Waqas

...
...

A critical unauthenticated remote-execution vulnerability (RufRoot, CVE-2026-59726; CVSS 10.0) was found in Ruflo deployments using the previous Docker Compose default: an exposed Model Context Protocol (MCP) bridge allowed attackers to invoke terminal_execute, run commands inside the bridge container, access 233 tools, steal AI-provider API keys and conversations, and poison persistent AgentDB memory; Ruflo released a fix in version 3.16.3 to lock the default configuration and recommended rotation of keys, rebuilding containers, and auditing AgentDB and logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.