CVE-2026-8321 Details
Description
A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware/runAuth.ts of the component runAuth Middleware. Performing a manipulation results in authentication bypass using alternate channel. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
An authentication bypass vulnerability has been identified in Inkeep Agents version 0.58.14. This issue resides within the runAuth middleware, specifically in the createDevContext function. The vulnerability allows unauthenticated attackers to bypass authentication by injecting custom x-inkeep-* headers, enabling them to impersonate any tenant, project, or agent. This exploitation can lead to unauthorized data access, privilege escalation, and excessive consumption of backend API resources, particularly those linked to LLM providers like OpenAI or Anthropic.
Users are advised to avoid deploying Inkeep Agents in development or test modes on public-facing servers. If such a deployment is necessary, ensure that appropriate safeguards are in place to prevent unauthorized access.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 11, 2026CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/inkeep/agents/ | [email protected] | ProductVendor |
| https://github.com/inkeep/agents/issues/3024 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/submit/811314 | [email protected] | Permission Required |
| https://vuldb.com/vuln/362608 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/362608/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Inkeep Agents | All versions |
CPE
Remediation
| |
| Inkeep Agents API | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | [email protected] |
Volerion