Download of code without integrity check in Automate - CVE-2026-9089
Published: May 21, 2026
Automate
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to download of code without integrity check in the agent plugin loading and self-update processes when processing components obtained during these operations. A remote attacker can supply a malicious component to execute arbitrary code.
Exploitation is limited to the adjacent network attack surface.