CVE-2026-59801

CRITICAL NUCLEI

9Router 0.4.41 - Unauthenticated API Exposure via /api/providers

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-59801 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the Next.js API routes under src/app/api/providers/*. Attackers can enumerate, create, modify, or delete provider connections to expose partial credentials, OAuth tokens, and API keys, redirect AI traffic to attacker-controlled servers, or cause complete denial of service by deleting all provider connections.

Nuclei Templates (1)

9Router - Unauthenticated LLM Provider API Exposure
CRITICALVERIFIEDby 0x_Akoko
Shodan: port:20128 http.html:"9Router"
FOFA: port="20128" || title="9Router"

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-vjc7-jrh9-9j86)
https://github.com/decolua/9router/security/advisories/GHSA-vjc7-jrh9-9j86
Third Party Advisory third-party-advisory
VulnCheck Advisory: 9Router 0.4.41 - Unauthenticated API Exposure via /api/providers
https://www.vulncheck.com/advisories/9router-unauthenticated-api-exposure-via-api-providers

Scores

CVSS v3 9.8
EPSS 0.0224
EPSS Percentile 81.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
decolua/9Router < 0.4.41
Published Jul 13, 2026
Tracked Since Jul 14, 2026