CVE-2026-59801
published 2026-07-13CVE-2026-59801: 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints…
PriorityP274critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
1.91%
77.6th percentile
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the Next.js API routes under src/app/api/providers/*. Attackers can enumerate, create, modify, or delete provider connections to expose partial credentials, OAuth tokens, and API keys, redirect AI traffic to attacker-controlled servers, or cause complete denial of service by deleting all provider connections.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| decolua | 9router | <= 0.4.41 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credenti
ghsa_unreviewed·2026-07-14
CVE-2026-59801 [CRITICAL] CWE-306 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credenti
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the Next.js API routes under src/app/api/providers/*. Attackers can enumerate, create, modify, or delete provider connections to expose partial credentials, OAuth tokens, and API keys, redirect AI traffic to attacker-controlled servers, or cause complete denial of service by deleting all provider connections.
VulDB
decolua 9Router up to 0.4.41 Management API /app/api/providers missing authentication
vuldb·2026-07-14·CVSS 9.8
CVE-2026-59801 [CRITICAL] decolua 9Router up to 0.4.41 Management API /app/api/providers missing authentication
A vulnerability labeled as very critical has been found in decolua 9Router up to 0.4.41. Affected by this issue is some unknown functionality of the file /app/api/providers of the component Management API. The manipulation results in missing authentication.
This vulnerability is reported as CVE-2026-59801. The attack can be launched remotely. No exploit exists.
No detection rules found.
Nuclei
9Router - Unauthenticated LLM Provider API Exposure
nuclei·CVSS 9.8
CVE-2026-59801 [CRITICAL] 9Router - Unauthenticated LLM Provider API Exposure
9Router - Unauthenticated LLM Provider API Exposure
9Router through version 0.4.41 contains an unauthenticated access vulnerability caused by missing authentication middleware in Next.js API routes under src/app/api/providers/*, letting remote attackers enumerate, create, modify, or delete provider connections, exploit requires no authentication.
Template:
id: CVE-2026-59801
info:
name: 9Router - Unauthenticated LLM Provider API Exposure
author: 0x_Akoko
severity: critical
description: |
9Router through version 0.4.41 contains an unauthenticated access vulnerability caused by missing authentication middleware in Next.js API routes under src/app/api/providers/*, letting remote attackers enumerate, create, modify, or delete provider connections, exploit requires no authentication.
impact
No writeups or analysis indexed.
2026-07-13
Published