CRITICAL 9.1 CVE-2026-85667 Published 4 Sept 2026

Xiaobei Webhook Endpoint Authentication Bypass

Worried this affects one of your servers?

Xiaobei versions up to 5.5.2 are affected by a lack of authentication and signature validation on webhook endpoints.

Xiaobei allows unauthenticated attackers to inject arbitrary messages into the agent pipeline via the /webhook_worktool handler.

Exploiting unvalidated media URL fetching, attackers can perform server-side request forgery against internal services.

Reference: CVE-2026-85667 on NVD

← Back to Security News