External risk intelligence

AgentGPT Incorrect Access Control Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51867

The vulnerability exists in an API router component of a web-based application. Such components are commonly deployed as internet-facing services or APIs to facilitate client-server communication, making them likely to be reachable from the public internet in typical deployment scenarios.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in AgentGPT's API allows unauthenticated access to sensitive data and operations. This issue could potentially lead to unauthorized data exposure or modification, impacting the integrity and confidentiality of information handled by the application. The main concern is confirming relevance and exposure to AgentGPT deployments.

  • Unauthenticated API access to data.
  • Critical issue impacting data security.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a request to an exposed API endpoint. This endpoint, located in the `agentRouter.ts` file, allows the caller to specify an object or tenant identifier without proper checks for ownership or membership. This lack of access control can allow an unauthenticated attacker to access or manipulate data.

  • No authentication required.
  • Caller-specified identifier bypasses access controls.
  • Unauthorized data access and modification.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to access or modify data by providing a crafted object or tenant identifier to an API endpoint. When supported by the advisory, this could impact system data and service behavior if the application improperly validates these identifiers before performing data operations.

  • System data could be accessed or modified.
  • Unauthenticated calls to an API endpoint.
  • Potential data corruption or unauthorized access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in `agentgpt`'s API router likely impacts application or platform teams responsible for managing external-facing services. The immediate first step is to identify all instances of this technology, determine their reachability and business criticality, and pinpoint the accountable owner for remediation planning.

  • Identify application and platform owners.
  • Verify external reachability and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is AgentGPT and how is it used?

AgentGPT is a software platform designed to facilitate autonomous AI agent workflows. It allows users to create, deploy, and manage AI agents that execute tasks by interacting with various services. Because it functions as a web-based application, it typically relies on API routers to manage communication between the user interface and the backend data stores.

What does Incorrect Access Control mean for CVE-2026-51867?

This vulnerability is classified as CWE-284, which refers to improper access control. In plain terms, it means the software fails to verify who a user is or whether they have permission to access specific data. For CVE-2026-51867, the application accepts requests to view or change data without checking if the requester actually owns or is authorized to interact with that specific workspace or tenant.

How does an attacker trigger this vulnerability?

An attacker triggers the bug by sending a specially crafted request to an API endpoint within the agentRouter component. They provide an identifier for an object or tenant, and the system processes the request without validating if the attacker belongs to that environment. Simply browsing the site or performing standard agent tasks does not trigger the bug; it requires specifically targeting these API paths with arbitrary identifiers.

Is my AgentGPT instance likely to be reachable by attackers?

According to Halo Surface Signal, this vulnerability is highly relevant if your instance is internet-facing. Because the flaw resides in an API router intended for client-server communication, it is often exposed to the public internet by default in many deployments. If your service is accessible from the web, the risk of external interaction with this unauthenticated path is significantly elevated.

What should I do if I am running AgentGPT?

Your first step is to perform an inventory of all AgentGPT instances within your environment. Verify whether these instances are exposed to the public internet and assess the sensitivity of the data they handle. Once identified, coordinate with your platform teams to restrict access to the affected API endpoints or apply updates if available, while keeping stakeholders informed of the current security status.

References