PT-2026-26152 · Unknown · Omnigen2-Rl

Valentin Lobstein

·

Published

2026-03-18

·

Updated

2026-03-19

·

CVE-2026-25873

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OmniGen2-RL (affected versions not specified)
Description OmniGen2-RL contains an unauthenticated remote code execution issue in the reward server component. Remote attackers can execute arbitrary commands by sending malicious HTTP POST requests. The root cause is insecure deserialization of request bodies using Python’s pickle module. The vulnerability does not require authentication, simplifying exploitation. The specific HTTP endpoint involved has not been detailed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-25873

Affected Products

Omnigen2-Rl