CVE-2026-59801
CRITICAL NUCLEI9Router 0.4.41 - Unauthenticated API Exposure via /api/providers
Title source: cnaExploitation Summary
CVE-2026-59801 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the Next.js API routes under src/app/api/providers/*. Attackers can enumerate, create, modify, or delete provider connections to expose partial credentials, OAuth tokens, and API keys, redirect AI traffic to attacker-controlled servers, or cause complete denial of service by deleting all provider connections.
Nuclei Templates (1)
9Router - Unauthenticated LLM Provider API Exposure
CRITICALVERIFIEDby 0x_Akoko
Shodan:
port:20128 http.html:"9Router"
FOFA:
port="20128" || title="9Router"
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-vjc7-jrh9-9j86)
https://github.com/decolua/9router/security/advisories/GHSA-vjc7-jrh9-9j86
Third Party Advisory third-party-advisory
VulnCheck Advisory: 9Router 0.4.41 - Unauthenticated API Exposure via /api/providers
https://www.vulncheck.com/advisories/9router-unauthenticated-api-exposure-via-api-providers
Scores
CVSS v3
9.8
EPSS
0.0224
EPSS Percentile
81.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-306
Status
published
Products (1)
decolua/9Router
< 0.4.41
Published
Jul 13, 2026
Tracked Since
Jul 14, 2026