CVE-2026-46711 - Soft Machine: Unauthenticated workspace API exposes arbitrary file read & directory exfiltration to any peer on the Fly private network
CVE ID :CVE-2026-46711 Published : Sept. 30, 2026, 5:16 p.m. | 1 hour, 22 minutes ago Description :Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly...