OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-46711

HIGH · CVSS 8.3 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Versions 0.2.247 and earlier of the Soft Machine Virtual Machine environment expose critical HTTP endpoints on port 8080 without authentication, allowing unauthenticated access to arbitrary files and entire project directories. This vulnerability enables any host within the same network to exploit the lack of a trust boundary, potentially leading to data breaches. Organizations using this software should prioritize immediate remediation, as there are currently no known patches available.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-46711
Severity
HIGH
CVSS
8.3
EPSS
0.27%

Original NVD Description

Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/<path>, /archive/<dir>) without any authentication or origin check. Any host that can reach TCP/8080 on a workspace can read arbitrary files under that workspace's /workspace root and download whole project trees as tar archives. Because every workspace shares the same Fly private 6PN and resolves all peer addresses via the unauthenticated _instances.internal TXT record, every other sm-ws-* machine on the same Fly app/org is a reachable, unauthenticated attacker — the trust boundary (workspace owner ↔ everyone-else) is missing. At time of publication, there are no publicly known patches.