CVE-2026-3693Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in Shy2593666979 AgentChat up to 2.3.0. This issue affects the function get_user_info/update_user_info of the file /src/backend/agentchat/api/v1/user.py of the component User Endpoint. This manipulation of the argument user_id causes improper control of resource identifiers. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-99

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-08); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-08: 3Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 103-0803-1203-13
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-083
Disclosure1General2
2026-03-121
Disclosure1
2026-03-131
Disclosure1
Full discourse5 posts
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-3693 - Shy2593666979 - AgentChat - https://www.redpacketsecurity.com/cve-alert-cve-2026-3693-shy2593666979-agentchat/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3693 #shy2593666979 #agentchat

    Post summary

    The tweet shares a link to a CVE alert page for CVE‑2026‑3693 affecting AgentChat, but provides no technical details, PoC, exploitation evidence, or patch information.

    0001082
    3.5K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3693 - Shy2593666979 AgentChat User Endpoint http://user.py update_user_info resource injection Intel Report: https://ift.tt/mCXYFV3

    Post summary

    The text is a threat alert about CVE‑2026‑3693, indicating a resource injection issue on the AgentChat endpoint, but no PoC, exploit, or patch details are provided.

    0001041
    347 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3693 (CVSS:6.9, HIGH) is Awaiting Analysis. A flaw has been found in Shy2593666979 AgentChat up to 2.3.0. This issue affects the function get_user_info/update_user_..https://nvd.nist.gov/vuln/detail/CVE-2026-3693 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A CVE-2026-3693 flaw in Shy2593666979 AgentChat with a CVSS score of 6.9 has been identified, but no public PoC, exploit, or patch information is provided yet.

    0000018
    172 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3693 (CVSS:6.9, HIGH) is Awaiting Analysis. A flaw has been found in Shy2593666979 AgentChat up to 2.3.0. This issue affects the function get_user_info/update_user_..https://nvd.nist.gov/vuln/detail/CVE-2026-3693 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE‑2026‑3693 with its CVSS score, affected product, and targeted functions, but provides no PoC, exploit code, or patch information.

    0000013
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3693 A flaw has been found in Shy2593666979 AgentChat up to 2.3.0. This issue affects the function get_user_info/update_user_info of the file /src/backend/agentchat/api/v1/u… https://www.cve.org/CVERecord?id=CVE-2026-3693

    Post summary

    A flaw was identified in Shy2593666979 AgentChat versions up to 2.3.0, affecting the get_user_info and update_user_info functions.

    00000110
    56.6K followersView on X

Explore more