CVE-2026-26057: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-26057 is an unsecured network binding vulnerability in the API Server component of Cisco's Skill Scanner (cisco-ai-skill-scanner) Python package. The flaw allows an unauthenticated, remote attacker to trigger a denial-of-service (DoS) condition or upload arbitrary files to the affected device. It affects all versions of Skill-scanner up to and including 1.0.1 when the API Server feature is enabled (disabled by default). The vulnerability was published on February 17, 2026, with a CVSS v3.1 score of 6.5 (Moderate) per the GitHub Advisory, though Feedly's NVD-sourced data assigns a higher score of 9.1 (Critical) (GitHub Advisory, Cisco Advisory).

Technical details

The root cause is classified as CWE-668 (Exposure of Resource to Wrong Sphere): in versions ≤ 1.0.1, the API Server defaulted to binding on 0.0.0.0 (all network interfaces) rather than localhost/127.0.0.1, inadvertently exposing the unauthenticated REST API to any reachable network. The fix (commit 1e35e57) changed the default bind address to localhost in api_cli.py, api_server.py, and updated documentation to warn that the server is intended for development use only and should not be exposed publicly. An attacker with network access to the exposed port can send unauthenticated HTTP requests to endpoints such as /scan-upload to upload ZIP files (including zip bombs) or flood the API to exhaust memory (GitHub Advisory, Fix Commit).

Impact

Successful exploitation can result in two distinct outcomes: (1) memory starvation leading to a denial-of-service condition on the hosting machine, potentially through uploaded zip bombs processed by the scanner; and (2) arbitrary file upload to any folder accessible by the process, which could be leveraged to plant malicious files, overwrite configuration, or facilitate further compromise. Because no authentication is required, any attacker with network access to the exposed API port can perform these actions without credentials. The vulnerability does not directly expose confidential data, but arbitrary file write capability could enable privilege escalation or persistence depending on the deployment environment (GitHub Advisory, Cisco Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The vulnerability is only exploitable when the API Server feature is explicitly enabled by the user, which is not the default configuration, limiting the exposed attack surface. The EPSS score is approximately 0.04% (0.000400), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Scan for hosts with TCP port 8000 (or custom configured port) open using tools like Shodan, Censys, or nmap, targeting environments where cisco-ai-skill-scanner ≤ 1.0.1 may be deployed with the API Server enabled.
  2. Verify API exposure: Send an HTTP GET request to http://<target>:8000/health — a 200 OK response with a JSON health status confirms the unauthenticated API is accessible.
  3. DoS via zip bomb upload: Craft a zip bomb (a deeply nested or highly compressed ZIP archive) and submit it via an HTTP POST to http://<target>:8000/scan-upload as a multipart form upload (file field). The server will attempt to process the archive, consuming excessive memory and potentially crashing the service.
  4. Arbitrary file upload: POST a crafted ZIP file to /scan-upload with a manipulated skill_directory parameter in a /scan request, targeting writable paths on the server filesystem to plant files in arbitrary locations.
  5. Achieve objective: Depending on filesystem permissions, uploaded files could include web shells, modified configuration files, or malicious scripts to enable persistence or further lateral movement (GitHub Advisory, Fix Commit).

Indicators of compromise

  • Network: Unexpected inbound HTTP connections to port 8000 (or configured API port) from external or non-localhost IP addresses; high-volume POST requests to /scan-upload or /scan endpoints from untrusted sources.
  • Logs: API server access logs showing requests from non-localhost IPs to /scan-upload, /scan, /health, or /analyzers endpoints; repeated large multipart file upload attempts; error logs indicating memory exhaustion or out-of-memory conditions.
  • File System: Unexpected files appearing in directories accessible to the skill-scanner process, particularly ZIP archives or scripts in non-standard locations; unusually large temporary files created during scan processing.
  • Process: The skill-scanner API server process consuming abnormally high memory (memory starvation); unexpected child processes spawned during ZIP processing (GitHub Advisory).

Mitigation and workarounds

Upgrade cisco-ai-skill-scanner to version 1.0.2 or later, which restricts the API Server to bind on localhost (127.0.0.1) by default. If immediate patching is not possible, disable the API Server entirely (it is not enabled by default) or manually start it with --host 127.0.0.1 to restrict access to localhost only. Additionally, implement network-level controls (firewall rules, security groups) to block external access to the API port (default 8000). Organizations using Docker deployments should avoid publishing the API port externally (GitHub Advisory, Fix Commit).

Community reactions

The vulnerability was discovered and fixed by Richard Tweed (@RichardoC), who is credited for both the research and fix implementation, with release engineering by Vineeth Sai Narajala (@vineethsai7). The advisory was published by Cisco's open source security team and coordinated through Cisco PSIRT. No significant broader media coverage or notable community commentary beyond the GitHub advisory has been identified (Cisco Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management