CVE-2026-90812
Received Received - Intake

Incorrect Privilege Assignment in Mercury Agent

Vulnerability report for CVE-2026-90812, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: VulDB

Description

A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation leads to incorrect privilege assignment. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cosmicstack-labs mercury-agent to 1.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in cosmicstack-labs mercury-agent up to version 1.2.0. It affects the checkShellCommand function in src/capabilities/permissions.ts, leading to incorrect privilege assignment. The issue allows remote attackers to manipulate permissions and may have been exploited already.

Impact Analysis

An attacker could remotely exploit this to gain unauthorized privileges or execute shell commands with elevated permissions. This may lead to data breaches, system compromise, or unauthorized access to sensitive resources.

Mitigation Strategies

Immediately upgrade cosmicstack-labs mercury-agent to a version beyond 1.2.0 if available. If no patch exists, disable the Shell Command Permission feature in src/capabilities/permissions.ts. Restrict network access to the affected component and monitor for unusual privilege escalation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90812. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart