SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-63769

HIGH · CVSS 7.7 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

A server-side request forgery vulnerability in Huginn allows authenticated users to exploit the fetch_url method of ScenarioImport, enabling them to send arbitrary HTTP requests through crafted URLs. This can lead to unauthorized access to internal network services, port enumeration, and exposure of sensitive credentials from cloud metadata endpoints. Organizations using Huginn should prioritize addressing this vulnerability to mitigate the risk of internal network exploitation and data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63769
Severity
HIGH
CVSS
7.7
EPSS
0.23%

Original NVD Description

Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via error signatures, and access cloud metadata endpoints to retrieve sensitive credentials.