Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
| CVE ID | CVE-2026-39987 |
| Vendor | Marimo |
| Affected Product | Marimo |
| Vulnerability Type | Vulnerability |
| CVSS Score | 9.5 (CRITICAL) |
| Actively Exploited | ✅ Yes — CISA KEV Listed |
| Patch Status | See Vendor Advisory → |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via cisa_kev) |
Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.