CVE-2026-25873Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests. Attackers can exploit insecure pickle deserialization of request bodies to achieve code execution on the host system running the exposed service.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-18); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-18: 3Mentions · 2026-03-19: 2Technical Details · 2026-03-18: 3Technical Details · 2026-03-19: 203-1803-19
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-183
Disclosure3
2026-03-192
Disclosure2
Full discourse5 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25873 - Critical OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious ... https://www.thehackerwire.com/vulnerability/CVE-2026-25873/ https://t.co/nfOjAC8N4D

    Post summary

    The post announces a critical remote code execution flaw (CVE‑2026‑25873) in OmniGen2‑RL’s reward server, detailing its nature but offering no PoC, exploitation evidence, or patch guidance.

    0001059
    138 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25873 OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands … https://www.cve.org/CVERecord?id=CVE-2026-25873

    Post summary

    CVE‑2026‑25873 reveals an unauthenticated remote code execution flaw in OmniGen2‑RL’s reward server, enabling attackers to run arbitrary commands.

    00000165
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25873 Unauthenticated Remote Code Execution in OmniGen2-RL Reward Server https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25873

    Post summary

    A new unathenticated RCE vulnerability (CVE‑2026‑25873) has been disclosed in the OmniGen2‑RL Reward Server.

    0000064
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-25873: CRITICAL] OmniGen2-RL has an unauthenticated remote code execution flaw in its reward server, allowing attackers to run commands through malicious HTTP requests. Exploiting insecure pickle d...#cve,CVE-2026-25873,#cybersecurity https://cvefind.com/CVE-2026-25873

    Post summary

    The post announces a critical remote code execution flaw in OmniGen2‑RL's reward server, detailing the vulnerability type and exploitation method but offering no proof of concept, patch, or evidence of active exploitation.

    0000081
    603 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25873: OmniGen2-RL Reward Server Unsafe... Pickle deserialization strikes again - unauthenticated RCE via HTTP POST to reward server, because someone thought seri... https://zerodaysignal.com/vulnerability/CVE-2026-25873 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑25873, explaining that OmniGen2‑RL Reward Server is vulnerable to an unauthenticated remote code execution due to unsafe pickle deserialization via HTTP POST.

    0000057
    155 followersView on X

Explore more