


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/application/websockets/share.py of the componen…
Published:
26 maart 2026 om 23:00:00
Alert date:
27 maart 2026 om 20:07:04
Source:
nvd.nist.gov
Web Technologies, Identity & Access
A critical authentication bypass vulnerability was discovered in OpenBMB XAgent 1.0.0, specifically in the check_user function of the ShareServer WebSocket Endpoint. The vulnerability allows remote attackers to manipulate the interaction_id argument to bypass authentication mechanisms. The exploit has been publicly disclosed and is available for use. The vendor was contacted about this disclosure but has not responded. This creates a significant security risk as the vulnerability can be remotely exploited.
Technical details
Mitigation steps:
Affected products:
OpenBMB XAgent
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-4959
https://gist.github.com/YLChen-007/531ec6b169f4b9ecbc8c2f0b2cd7c5ee
https://vuldb.com/?ctiid.353836
https://vuldb.com/?id.353836
https://vuldb.com/?submit.777622
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
