SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-62327

CRITICAL · CVSS 9.1 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability allows remote attackers to exploit an unauthenticated endpoint in 9Router versions up to 0.4.41, enabling them to retrieve plaintext API keys for all connected AI provider accounts. This can lead to unauthorized access, billing fraud, and quota exhaustion due to the exposure of sensitive account information. Organizations using affected versions should prioritize immediate remediation to prevent potential exploitation and financial impact.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-62327
Severity
CRITICAL
CVSS
9.1
EPSS
0.37%

Original NVD Description

9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single unauthenticated request to the /api/usage/stats endpoint. Attackers can exploit the missing authentication middleware on the Next.js API route to obtain full API key strings alongside token counts, cost breakdowns, and request metadata, enabling unauthorized use of connected AI provider accounts, billing fraud, and quota exhaustion.