SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-41461

HIGH · CVSS 8.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-04-23 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.5. It may be remotely exploitable.

CVE
CVE-2026-41461
Severity
HIGH
CVSS
8.5
EPSS
0.30%

Original NVD Description

SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplied input passed via the uri request parameter is not sanitized before being used to construct outbound HTTP requests. Authenticated remote attackers can supply arbitrary URLs including internal network addresses and loopback addresses to cause the server to issue HTTP requests to attacker-controlled destinations, enabling internal network enumeration and access to services not intended to be externally reachable.

Related CVEs

Other vulnerabilities affecting the same vendor(s)