
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26057 is an unsecured network binding vulnerability in the API Server component of Cisco's Skill Scanner (cisco-ai-skill-scanner) Python package. The flaw allows an unauthenticated, remote attacker to trigger a denial-of-service (DoS) condition or upload arbitrary files to the affected device. It affects all versions of Skill-scanner up to and including 1.0.1 when the API Server feature is enabled (disabled by default). The vulnerability was published on February 17, 2026, with a CVSS v3.1 score of 6.5 (Moderate) per the GitHub Advisory, though Feedly's NVD-sourced data assigns a higher score of 9.1 (Critical) (GitHub Advisory, Cisco Advisory).
The root cause is classified as CWE-668 (Exposure of Resource to Wrong Sphere): in versions ≤ 1.0.1, the API Server defaulted to binding on 0.0.0.0 (all network interfaces) rather than localhost/127.0.0.1, inadvertently exposing the unauthenticated REST API to any reachable network. The fix (commit 1e35e57) changed the default bind address to localhost in api_cli.py, api_server.py, and updated documentation to warn that the server is intended for development use only and should not be exposed publicly. An attacker with network access to the exposed port can send unauthenticated HTTP requests to endpoints such as /scan-upload to upload ZIP files (including zip bombs) or flood the API to exhaust memory (GitHub Advisory, Fix Commit).
Successful exploitation can result in two distinct outcomes: (1) memory starvation leading to a denial-of-service condition on the hosting machine, potentially through uploaded zip bombs processed by the scanner; and (2) arbitrary file upload to any folder accessible by the process, which could be leveraged to plant malicious files, overwrite configuration, or facilitate further compromise. Because no authentication is required, any attacker with network access to the exposed API port can perform these actions without credentials. The vulnerability does not directly expose confidential data, but arbitrary file write capability could enable privilege escalation or persistence depending on the deployment environment (GitHub Advisory, Cisco Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The vulnerability is only exploitable when the API Server feature is explicitly enabled by the user, which is not the default configuration, limiting the exposed attack surface. The EPSS score is approximately 0.04% (0.000400), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
nmap, targeting environments where cisco-ai-skill-scanner ≤ 1.0.1 may be deployed with the API Server enabled.http://<target>:8000/health — a 200 OK response with a JSON health status confirms the unauthenticated API is accessible.http://<target>:8000/scan-upload as a multipart form upload (file field). The server will attempt to process the archive, consuming excessive memory and potentially crashing the service./scan-upload with a manipulated skill_directory parameter in a /scan request, targeting writable paths on the server filesystem to plant files in arbitrary locations./scan-upload or /scan endpoints from untrusted sources./scan-upload, /scan, /health, or /analyzers endpoints; repeated large multipart file upload attempts; error logs indicating memory exhaustion or out-of-memory conditions.Upgrade cisco-ai-skill-scanner to version 1.0.2 or later, which restricts the API Server to bind on localhost (127.0.0.1) by default. If immediate patching is not possible, disable the API Server entirely (it is not enabled by default) or manually start it with --host 127.0.0.1 to restrict access to localhost only. Additionally, implement network-level controls (firewall rules, security groups) to block external access to the API port (default 8000). Organizations using Docker deployments should avoid publishing the API port externally (GitHub Advisory, Fix Commit).
The vulnerability was discovered and fixed by Richard Tweed (@RichardoC), who is credited for both the research and fix implementation, with release engineering by Vineeth Sai Narajala (@vineethsai7). The advisory was published by Cisco's open source security team and coordinated through Cisco PSIRT. No significant broader media coverage or notable community commentary beyond the GitHub advisory has been identified (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."