Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

Marimo Pre-Authorization Remote Code Execution (CVE-2026-39987)

Historical catalog analysis: CISA added this entry on April 23, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.

What the vulnerability is

CVE-2026-39987 is a pre-authorization remote code execution (RCE) vulnerability identified in Marimo. The flaw, categorized under CWE-306 (Missing Authentication for Critical Function), allows an unauthenticated attacker to obtain shell access and execute arbitrary system commands on the host environment.

Exposure and applicability

This vulnerability applies to organizations deploying Marimo instances that are accessible over a network without sufficient pre-authorization controls. Because the vulnerability allows for unauthenticated access, any exposed instance is potentially susceptible to remote command execution. Infrastructure owners should prioritize identifying all active Marimo deployments, particularly those residing in cloud environments or exposed via public-facing interfaces.

Remediation priorities

Based on our analysis of the reported risk, we recommend the following priority actions for vulnerability management teams:

  1. Immediate Mitigation Deployment: Apply the specific mitigations provided by the vendor. If a patch or configuration change is available, it should be deployed across all identified instances to close the RCE path.
  2. Cloud Service Review: For deployments hosted in cloud environments, review and apply guidance consistent with BOD 22-01 to ensure that the vulnerability is not being leveraged through cloud-specific exposure paths.
  3. Service Decommissioning: In scenarios where vendor mitigations are unavailable or cannot be verified, the most effective way to reduce exposure is to discontinue use of the product until a secure version is available.

How to validate remediation

Verification must go beyond a simple version check, as configuration errors can leave a system exposed even after a patch is applied. To verify that the risk has been reduced, defenders should:

  • Confirm Mitigation Application: Cross-reference deployed versions and configurations against the vendor’s specific security advisory requirements.
  • Test Authorization Boundaries: Use authorized testing to confirm that critical functions—specifically those allowing shell access or command execution—now require valid authentication and are no longer accessible to unauthenticated requests.
  • Verify Network Isolation: Ensure that if mitigations are pending, the service is isolated from untrusted networks via firewall rules or VPC restrictions to prevent external reachability.

Limits and open questions

While the vulnerability allows for shell access, the source does not provide data on whether this flaw has been utilized in known ransomware campaigns. Additionally, while CISA has established a remediation deadline of May 7, 2026, for federal agencies, this date serves as a risk indicator rather than a mandatory requirement for non-federal organizations. Residual risk remains if the application is deployed with excessive system privileges, as RCE could lead to full host compromise regardless of the initial entry point.

Source and editorial note

CVE-2026-39987: Marimo Remote Code Execution Vulnerability · Source date: April 23, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Archive date: April 26, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 13, 2026 at 00:39 UTC.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment