CVE-2026-26020Disclosure(agpt / autogpt_platform)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch agpt autogpt_platform systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.48, an authenticated user could achieve Remote Code Execution (RCE) on the backend server by embedding a disabled block inside a graph. The BlockInstallationBlock — a development tool capable of writing and importing arbitrary Python code — was marked disabled=True, but graph validation did not enforce this flag. This allowed any authenticated user to bypass the restriction by including the block as a node in a graph, rather than calling the block's execution endpoint directly (which did enforce the flag). This vulnerability is fixed in 0.6.48.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • autogpt_platform

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 10d ago at 1 mentions (2026-02-12); latest day: 1
  • 11 total mentions across 11 days

Affected systems

Vendors
Products
autogpt_platform

Deep dive

Activity timeline11 mentions / 11d
00111Mentions · 2026-02-12: 1Mentions · 2026-02-13: 1Mentions · 2026-02-15: 1Mentions · 2026-03-07: 1Mentions · 2026-03-08: 1Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1PoC Mentioned / Linked · 2026-03-07: 1PoC Mentioned / Linked · 2026-03-09: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-03-07: 1Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-15: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-14: 102-1202-1302-1503-0703-0803-0903-1003-1103-1203-1303-14
Signal classification4 categories
Disclosure
654.5%
Patch
327.3%
General
19.1%
Disclousure
19.1%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-121
General1
2026-02-131
Patch1
2026-02-151
Disclosure1
2026-03-071
Disclosure1
2026-03-081
Patch1
2026-03-091
Disclosure1
2026-03-101
Disclosure1
2026-03-111
Disclousure1
2026-03-121
Disclosure1
2026-03-131
Patch1
2026-03-141
Disclosure1
Full discourse11 posts
  • CVE@CVEnew
    General

    CVE-2026-26020 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.48, an a… https://www.cve.org/CVERecord?id=CVE-2026-26020

    Post summary

    The post references CVE‑2026‑26020 but offers no additional detail on exploitation, patching, or technical specifics.

    00020219
    56.5K followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    New vulnerability disclosed: CVE-2026-26020 with a CVSS score of 8.8. AutoGPT is a platform that allows users to create,.... Worth reviewing if this affects your stack. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    A new high‑severity vulnerability, CVE-2026‑26020 with a CVSS of 8.8, has been announced, accompanied by a link to further details, but no exploit code, patch, or active‑exploitation information is provided.

    0000028
    98 followersView on X
  • Prateek Tomar@Prateektomar
    Patch

    CVE-2026-26020 has been published with a CVSS score of 8.8. AutoGPT is a platform that allows users to create,.... Add it to your patching queue if applicable. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    CVE-2026-26020 has been disclosed with a CVSS of 8.8; the brief notes advise adding it to the patch queue.

    0000029
    95 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    Security advisory: CVE-2026-26020 with a CVSS score of 8.8. AutoGPT is a platform that allows users to create,.... Check if you need to take action. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    The text announces an advisory for CVE‑2026‑26020 with a high CVSS score, but it lacks PoC details, exploit code, active exploitation evidence, or patch information, indicating a straightforward disclosure.

    0000024
    93 followersView on X
  • Prateek Tomar@Prateektomar
    Disclousure

    Security advisory: CVE-2026-26020 with a CVSS score of 8.8. AutoGPT is a platform that allows users to create,.... Check if you need to take action. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    A security advisory highlights CVE-2026-26020 with a CVSS score of 8.8 and directs readers to an exploit radar for further details, but provides no PoC, patch, or evidence of active exploitation.

    0000033
    95 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    New vulnerability disclosed: CVE-2026-26020 with a CVSS score of 8.8. AutoGPT is a platform that allows users to create,.... Worth reviewing if this affects your stack. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    The post announces a newly disclosed CVE-2026-26020 with a CVSS of 8.8 and links to threatops for more details, but offers no PoC, exploit, or patch information.

    0000033
    92 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    Security advisory: CVE-2026-26020 with a CVSS score of 8.8. AutoGPT is a platform that allows users to create,.... Check if you need to take action. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    An advisory notes CVE‑2026‑26020 has a CVSS score of 8.8, directs readers to an external link for details, and does not provide exploit code, patch information, or evidence of active exploitation.

    0000036
    91 followersView on X
  • Prateek Tomar@TomarPrateek23
    Patch

    CVE-2026-26020 has been published with a CVSS score of 8.8. AutoGPT is a platform that allows users to create,.... Add it to your patching queue if applicable. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    The post notes that CVE-2026-26020, with a CVSS score of 8.8, has been published and advises adding it to patch queues.

    0000042
    91 followersView on X
  • Prateek Tomar@TomarPrateek23
    Disclosure

    CVE-2026-26020 has been published with a CVSS score of 8.8. AutoGPT is a platform that allows users to create,.... Add it to your patching queue if applicable. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    CVE-2026-26020 is a newly published vulnerability with a high CVSS score of 8.8; a link to additional exploit information is provided and users are advised to add it to their patching queue.

    0000033
    91 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-26020: AutoGPT Affected by Remote Code ... Devastating auth bypass in AutoGPT exposes critical validation gap; embed disabled BlockInstallationBlock in graph to a... https://zerodaysignal.com/vulnerability/CVE-2026-26020 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces the discovery of CVE‑2026‑26020 in AutoGPT, describing an authentication bypass that exposes a critical validation gap.

    0000075
    131 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: AutoGPT (<0.6.48) allows authenticated users RCE via improper authorization. Upgrade now to protect your AI workflows! 🔒 https://radar.offseq.com/threat/cve-2026-26020-cwe-285-improper-authorization-in-s-31ca744c #OffSeq #AutoGPT #Vulnerability #AIsecurity https://t.co/XcRdfcZgq8

    Post summary

    The tweet highlights a critical RCE vulnerability in AutoGPT (v < 0.6.48) and urges users to upgrade to mitigate the issue.

    0000046
    268 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appagptautogpt_platform---

Explore more