Sploitus

CVE-2026-56679

No indexed exploits for CVE-2026-56679 yet

9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body to persistent settings without a field whitelist, allowing an authenticated user to set security-critical fields such as requireLogin and disable authentication for the whole application, exposing protected routes such as /api/keys and /api/providers to unauthenticated access. This issue is reported as fixed in version 0.5.4.

Affected products
9Router
Fix
Available
CVSS 4.0
8.7 HIGH
EPSS
0.3% (25th percentile)
Weakness
CWE-915
NVD status
Deferred
Published
2026-07-15
CVE-2026-56679 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-56679 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-56679 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.