CVE-2026-85663: Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch

Published Sep 4, 2026
·
Updated

Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs.

Event History

Sep 4, 2026
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments running the Aim 3.29.1 remote tracking server are exposed because it accepts unauthenticated requests and dispatches methods without an allowlist. Any attacker able to reach that server over the network can exploit the issue.

2

What access does an attacker need?

No authentication, privileges, or user interaction are required. An attacker can register clients, create Repo resources, and invoke arbitrary methods through the remote tracking service.

3

What could an attacker do through the vulnerable service?

An attacker may read experiments or delete runs. The issue is also described as remote code execution through arbitrary method dispatch.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203