SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-65558

MEDIUM · CVSS 5.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

AffiliateX versions up to 2.3.5 are vulnerable to an unauthenticated Server Side Request Forgery (SSRF) attack, which could allow an attacker to manipulate server requests and potentially access sensitive internal resources. Organizations using this software should prioritize patching or upgrading to mitigate the risk of unauthorized access and data exposure. This vulnerability is particularly relevant for businesses that rely on AffiliateX for affiliate marketing services.

CVE
CVE-2026-65558
Severity
MEDIUM
CVSS
5.4
EPSS
0.13%

Original NVD Description

Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.