CVE-2026-108739
Received Received - Intake

OpenAgents Workspace Information Disclosure via Unauthenticated API

Vulnerability report for CVE-2026-108739, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

OpenAgents Workspace backend through launcher-v1.0.17 contains an information disclosure vulnerability that allows unauthenticated attackers to list all workspaces via GET /v1/workspaces. Attackers can read the unmasked browserfabric_api_key in each workspace's settings map, along with workspace ids, slugs, creator emails and member lists.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openagents-org OpenAgents 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an information disclosure flaw in OpenAgents Workspace backend (versions up to launcher-v1.0.17). It allows unauthenticated attackers to list all workspaces via an unauthenticated GET request to /v1/workspaces. The response includes sensitive data like unmasked browserfabric_api_key values, workspace IDs, slugs, creator emails, and member lists.

Detection Guidance

To detect this vulnerability, check if your OpenAgents Workspace backend is running a vulnerable version (launcher-v1.0.16 or launcher-v1.0.17). Send an unauthenticated GET request to /v1/workspaces and inspect the response for unmasked browserfabric_api_key values or workspace metadata. Example command: curl -X GET http://<target-ip>:<port>/v1/workspaces

If the response includes raw API keys or sensitive workspace details without authentication, the system is likely vulnerable.

Impact Analysis

Attackers can use the exposed browserfabric_api_key to impersonate the workspace and perform unauthorized actions with Browser Fabric services. They can also access workspace metadata, including user emails and member lists, potentially leading to further attacks or data breaches.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to personal data (emails, member lists) and sensitive credentials. It exposes protected health information or personal data without consent, leading to compliance violations and potential legal consequences.

Mitigation Strategies

Immediately upgrade to a patched version of OpenAgents Workspace backend if available. If not, restrict access to the /v1/workspaces endpoint via network policies or firewall rules. Rotate all exposed browserfabric_api_key values and audit workspace configurations.

Monitor for unauthorized access attempts and review logs for suspicious GET requests to /v1/workspaces.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108739. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart