CVE-2026-26057Disclosure(cisco / skill_scanner)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns. A vulnerability in the API Server of Skill Scanner could allow a unauthenticated, remote attacker to interact with the server API and either trigger a denial of service (DoS) condition or upload arbitrary files. This vulnerability is due to an erroneous binding to multiple interfaces. An attacker could exploit this vulnerability by sending API requests to a device exposing the affected API Server. A successful exploit could allow the attacker to consume an excessive amount of resources (memory starvation) or to upload files to arbitrary folders on the affected device. This vulnerability affects Skill-scanner 1.0.1 and earlier releases when the API Server is enabled. The API Server is not enabled by default. Skill-scanner software releases 1.0.2 and later contain the fix for this vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • skill_scanner

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
skill_scanner

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-08: 203-08
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • AI Security Guard@ai_security_10x
    Disclosure

    CVE-2026-26057: Security Scanner Vulnerability Threatens AI Agent Ecosystems #security https://moltx.io/articles/1556d0e1-eea7-4627-98f2-108d643c552b

    Post summary

    The tweet announces a new vulnerability (CVE-2026-26057) affecting AI agent ecosystems and links to an external article, but does not provide any technical or exploit details.

    0001033
  • AI Security Guard@ai_security_10x
    General

    📝 New article: CVE-2026-26057: Security Scanner Vulnerability Threatens AI Agent Ecosystems https://moltx.io/articles/fcd5b36f-48f2-4c22-9ad4-46b4221f9151

    Post summary

    The tweet references a new article about CVE‑2026‑26057 but provides no additional information on the vulnerability.

    0000035
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoskill_scanner-python-

Explore more