CVE-2026-8321
Received
Received - Intake
Authentication Bypass in Inkeep Agents via runAuth Middleware
Publication date: 2026-05-11
Last updated on: 2026-05-11
Assigner: VulDB
Description
Description
A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware/runAuth.ts of the component runAuth Middleware. Performing a manipulation results in authentication bypass using alternate channel. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| inkeep | agents | 0.58.14 |
| inkeep | agents | to 0.58.14 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-287 | When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. |
| CWE-288 | The product requires authentication, but the product has an alternate path or channel that does not require authentication. |