CVE-2026-27598 affects Dagu workflow engine versions up to 1.16.7, where the CreateNewDAG API endpoint allows authenticated users with write permissions to write arbitrary YAML files to the filesystem due to improper input validation. This vulnerability, rated Medium severity (CVSS 6.5), has a low attack complexity and can lead to remote code execution by overwriting configuration files or injecting malicious DAGs. There is currently no evidence of active exploitation, public exploit code, or KEV listing, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.16.7CPE matchmatch criteria | cpe:2.3:a:dagu:dagu:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.