CVE-2026-18998
A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/su
CVSS
6.3
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 6, 2026 · Last modified: Aug 6, 2026 · CWE-266 · CWE-285
Not enough EPSS history yet.
A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.ts of the component delegate_task Tool. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
- github.comhttps://github.com/cosmicstack-labs/mercury-agent/
- github.comhttps://github.com/cosmicstack-labs/mercury-agent/issues/74
- vuldb.comhttps://vuldb.com/cve/CVE-2026-18998
- vuldb.comhttps://vuldb.com/submit/862628
- vuldb.comhttps://vuldb.com/submit/862629
- vuldb.comhttps://vuldb.com/vuln/386381
- vuldb.comhttps://vuldb.com/vuln/386381/cti
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-190664.3 MED—
———A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unknown function of the file view_students.php. Such manipulation of the argument class_group leads to authorization bypass. The attack may be launched remotely.4hCVE-2026-190644.3 MED—
———A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument ID results in authorization bypass. The attack can be launched remotely.4hCVE-2026-183679.3 CRI—
———A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.4hCVE-2026-666629.8 CRI—
———Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.10hCVE-2026-655597.2 HIG—
———Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.10hCVE-2026-655079.8 CRI—
———Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.4h