CVE-2026-55176 - Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SHARED_SECRET` bearer token
CVE ID :CVE-2026-55176 Published : Sept. 30, 2026, 5:16 p.m. | 1 hour, 22 minutes ago Description :Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and...