SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-72846

MEDIUM · CVSS 6.4 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Lightdash is vulnerable due to improper validation of webhook URLs, allowing users to create scheduled deliveries that can direct the server to send POST requests to internal and private addresses, potentially exposing sensitive information about internal services. The impact includes the ability to probe internal network configurations and access cloud metadata endpoints, which could lead to further exploitation. Organizations using affected versions of Lightdash should prioritize remediation to mitigate the risk of internal service exposure and potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72846
Severity
MEDIUM
CVSS
6.4
EPSS
0.26%
Microsoft

Original NVD Description

Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsClient.ts. In affected versions both call fetch on the stored URL directly. The validatePublicHttpUrl helper in packages/backend/src/utils/ssrfProtection.ts, used for MCP server URLs, is not applied on either path, and the webhook fields carry no server-side URL constraint. A user able to create or trigger a scheduled delivery can therefore direct the server to issue POST requests to private, loopback and link-local addresses, including cloud metadata endpoints, and can distinguish reachable internal services from unreachable ones through the resulting errors. The upstream response is never returned to the requester; on a failure status its body is written to the server log instead. Version 1.146.4 routes both clients through postSchedulerWebhook from packages/backend/src/utils/schedulerWebhookValidation rather than calling fetch directly.