Description
An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanisms. Once inside the web application, the attacker can use any of its features regardless of the authorisation method used.
References (1)
Core 1
Core References
Scores
CVSS v4
6.9
EPSS
0.0042
EPSS Percentile
33.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-287
Status
published
Products (1)
Thesamur/AutoGPT
All versions
Published
Feb 19, 2026
Tracked Since
Feb 19, 2026