CVE-2026-9317 CRITICAL

CVE-2026-9317: Nango < 0.71.6 Missing Authentication RCE via runner tRPC server

Vendor Nangohq
Product nango
Weakness CWE-306 · Missing auth
Published September 4, 2026
Last update September 4, 2026

CVSS base score

9.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with network access to the runner port can send requests to the unauthenticated start procedure, bypassing the unenforced RUNNER_SECRET_KEY environment variable, to achieve remote code execution within the runner process.

Key dates

02Disclosure timeline

September 4, 2026 CVE published

Related vulnerabilities

04Related CVE