Junglewise Threat Intelligence

CVE-2026-90620: 0x4m4 HexStrike AI authentication bypass in API endpoint

CVE-2026-90620 · Severity: high · CVSS 7.3 · Published 2026-09-14

Technologies: 0x4m4 HexStrike AI. Vendors: 0x4m4.

Executive brief

HexStrike AI is an AI-powered security analysis tool with a remote API server. A missing authentication flaw in the API command endpoint allows unauthenticated remote attackers to interact with the server without proper credentials, potentially leading to unauthorized command execution, data exposure, or service disruption.

Technical details

The vulnerability is a missing authentication issue in an unknown function within the hexstrike_server.py component's API Command Endpoint. The flaw allows remote attackers to bypass authentication controls and access the API without valid credentials, enabling unauthorized operations. The attack vector is network-based and requires no authentication or user interaction. The product uses continuous delivery with rolling releases, so specific affected version numbers are not available. The vulnerability has been publicly disclosed but is not currently known to be exploited in the wild. No patch has been released as of the advisory date.

Affected products

  • 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: advisory

References

Related threats