CVE-2026-24516

HIGH

DigitalOcean Droplet Agent - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2026-24516. PoCs published by adminlove520, poxsky.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-24516, an unauthenticated root RCE vulnerability in DigitalOcean Droplet Agent. It explains the exploit chain involving metadata poisoning and a TCP side-channel trigger, but does not include functional exploit code.

Description

A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshooting/actioner/actioner.go) processes metadata from the metadata service endpoint and executes commands specified in the TroubleshootingAgent.Requesting array without adequate input validation. While the code validates that artifacts exist in the validInvestigationArtifacts map, it fails to sanitize the actual command content after the "command:" prefix. This allows an attacker who can control metadata responses to inject and execute arbitrary OS commands with root privileges. The attack is triggered by sending a TCP packet with specific sequence numbers to the SSH port, which causes the agent to fetch metadata from http://169.254.169.254/metadata/v1.json. The vulnerability affects the command execution flow in internal/troubleshooting/actioner/actioner.go (insufficient validation), internal/troubleshooting/command/exec.go (direct exec.CommandContext call), and internal/troubleshooting/command/command.go (command parsing without sanitization). This can lead to complete system compromise, data exfiltration, privilege escalation, and potential lateral movement across cloud infrastructure.

Exploits (3)

github WRITEUP 3 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2026/CVE-2026-24516

This repository provides a detailed technical analysis of CVE-2026-24516, an unauthenticated root RCE vulnerability in DigitalOcean Droplet Agent. It explains the exploit chain involving metadata poisoning and a TCP side-channel trigger, but does not include functional exploit code.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Complex
Reliability
Theoretical
Target: DigitalOcean Droplet Agent (droplet-agent) <= v1.3.2
No auth needed
Prerequisites: SSRF in a hosted application to proxy requests to the link-local metadata service · ability to spoof TCP packets to trigger the agent
devstral-2 · analyzed May 02, 2026 Full analysis →
nomisec WRITEUP 1 stars
by poxsky · poc
https://github.com/poxsky/CVE-2026-24516-DigitalOcean-RCE

The repository provides a detailed technical analysis of CVE-2026-24516, a critical pre-authentication remote code execution vulnerability in DigitalOcean Droplet Agent up to v1.3.2. It includes specifics about the vulnerable components, the triggering mechanism (port knocking), and a proof-of-concept payload.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: DigitalOcean Droplet Agent (up to v1.3.2)
No auth needed
Prerequisites: Network access to target · Ability to send TCP packets to port 22 · Access to modify metadata payload
devstral-2 · analyzed May 03, 2026 Full analysis →
nomisec WRITEUP
by poxsky · poc
https://github.com/poxsky/CVE-2026-24516-DigitalOcean-RCE.

This repository provides a detailed technical analysis of CVE-2026-24516, an unauthenticated root RCE vulnerability in DigitalOcean Droplet Agent. It explains the exploit chain involving metadata poisoning, TCP side-channel signaling, and command injection, but does not include functional exploit code.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Complex
Reliability
Theoretical
Target: DigitalOcean Droplet Agent (droplet-agent) <= v1.3.2
No auth needed
Prerequisites: SSRF in a hosted application to proxy requests to the link-local metadata service · ability to spoof TCP packets to trigger the agent
devstral-2 · analyzed Apr 09, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0013
EPSS Percentile 32.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
digitalocean/droplet-agent 0Go
Published Mar 23, 2026
Tracked Since Mar 23, 2026