CVE-2026-77776 – Headroom

CVSS 9.1 CRITICAL Critical - Same Day Deployment

“A trusted identity header can expose one user’s AI memory to another.”

Headroom fixed a critical authorization flaw in its LLM proxy that allowed clients to supply another user’s identifier and read or modify that user’s stored LLM memory. CVE-2026-77776 affects versions before 0.36.1. The CVSS score is 9.1, which is Critical severity.

The fix strengthens memory identity handling by restricting when the user-supplied header is trusted and otherwise binding identity to the authenticated caller or local operating system user.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-639
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.