Security researchers have published the details and proof-of-concept exploit for a critical OmniRoute RCE flaw. This severe vulnerability allows remote attackers to execute arbitrary commands without authentication. Administrators must apply the latest patches immediately to secure their deployments.
- CVE: CVE-2026-88062
- CVSS: 9.5 (Critical · CVSSv4)
- Product: diegosouzapw OmniRoute
- Affected: < 3.8.49
- Impact: OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy This Threat Matters
OmniRoute functions as a unified AI gateway. It manages hundreds of large language models for enterprise applications. Industry estimates indicate that thousands of developers use this platform to reduce API costs. Therefore, a complete server compromise poses a massive risk. Attackers can steal API keys, exfiltrate sensitive prompts, and pivot into internal networks.
How the Attack Works
The OmniRoute RCE flaw originates in the custom agent registration endpoint. An attacker sends a malicious HTTP request to the server. They manipulate the binary and version command parameters during this process.
The application fails to sanitize these inputs properly. Consequently, it executes the attacker-supplied JavaScript directly inside the server container. The system then evaluates this code synchronously.
This mechanism grants the attacker the ability to run operating system commands. If the server lacks a management password, this attack requires zero authentication. A public proof-of-concept exploit code is currently available. However, security teams have not confirmed active exploitation in the wild. You can review the complete technical breakdown in the official OmniRoute security advisory.
Affected Versions
This critical vulnerability affects OmniRoute installations running versions prior to 3.8.49.
Patch and Mitigation Steps
Users must upgrade to version 3.8.49 or later immediately. This patch fixes the validation logic and enforces strict authentication checks.
If immediate patching is impossible, you must secure the management interface. You should configure a strong management password. Additionally, you must enable the login requirement setting. Finally, you should restrict network access to trusted hosts using strict firewall rules.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!