LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-39987: Marimo Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 23, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 7, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-39987 to its Known Exploited Vulnerabilities catalog on Apr 23, 2026, with a federal patch deadline of May 7, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

Marimo contains a pre-authorization remote code execution vulnerability. An unauthenticated attacker can obtain shell access and execute arbitrary system commands on affected instances. The issue matters because it allows direct remote compromise without credentials.

How it works

The weakness is categorized as CWE-306, Missing Authentication for Critical Function. The product exposes functionality that permits command execution before any authentication check occurs.

An attacker can reach the affected endpoint or interface directly and issue system commands. No valid session or credentials are required. Specific request patterns or parameters that trigger the flaw must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Marimo instances are typically deployed as self-hosted applications or services that accept external connections. Inventory all deployments by scanning for the product name in container registries, package managers, configuration management databases, and cloud workloads.

Exact versions and configurations to test must be confirmed against the vendor advisory.

How to remediate

Apply mitigations per the vendor instructions. For cloud-hosted instances, follow applicable BOD 22-01 guidance. If mitigations cannot be applied, discontinue use of the product.

If you can't patch immediately

Until the vendor mitigation can be applied, reduce exposure through network controls and access restrictions. Segment Marimo instances so they are reachable only from trusted management networks. Disable or restrict the affected feature if the product permits it. Monitor inbound traffic and process execution for signs of unauthorized command activity. If no effective controls are available, discontinue use of the product as stated in the CISA required action.

If your data may have been exposed

Pre-authorization remote code execution can lead to full system compromise and data access. Organizations can run a free exposure scan of their email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMarimo · Marimo
WeaknessCWE-306
Added to CISA KEVApr 23, 2026
Federal patch deadlineMay 7, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities