Skip to content

CVE-2026-59726: Critical Vulnerability in Ruflo Endangers AI Agents Through Exposed MCP Interface

In a nutshell: An unauthenticated MCP bridge in Ruflo enables full access to AI agents, LLM API keys and persistent agent memory with a single HTTP request.

A vulnerability in the open-source platform Ruflo allows unauthenticated attackers to take over AI agents via an exposed Model-Context Protocol bridge (MCP) and establish a complete foothold in enterprise environments. The vulnerability CVE-2026-59726 with CVSS score 10.0 affects versions before 3.16.3.

Noma Security has documented a critical vulnerability in Ruflo, known as RufRoot. The issue lies in the MCP bridge, which is available without authentication by default and directly accesses 233 tools through which AI agents interact with enterprise systems. These tools include shell access, database operations, agent management and storage functions.

Attackers can execute arbitrary code via a simple HTTP request to the unauthenticated /mcp endpoint — for example through Ruflo’s terminal_execute tool — and thus execute commands in the underlying container. The researchers demonstrated in their proof-of-concept that within a standard Ruflo deployment on AWS EC2, they were able to steal LLM API keys from environment variables, retrieve conversations from MongoDB and deploy attacker-controlled agent swarms.

Particularly critical is the so-called memory poisoning: by injecting malicious entries into Ruflo’s AgentDB pattern store, future AI responses can be influenced with attacker-controlled instructions. These poisoned memory entries can remain in the trusted data store after the original compromise and sustainably manipulate agent behaviour.

Industry experts warn that the problem extends beyond Ruflo. Since MCP platforms were often deployed quickly and prioritised simple configurability over authentication, similar risks exist in other orchestration tools. Particularly the treatment of persistent, writable agent memory as security boundaries — who is allowed to write and how system-generated entries can be distinguished from attacker entries — is solved in few platforms.


Source: www.csoonline.com · Published 30 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: