OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-76898

HIGH · CVSS 7.7 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability affects draw.io versions prior to 30.3.8, allowing unauthenticated users to exploit the application by sending requests that can fetch internal IPv6 resources, potentially exposing sensitive cloud metadata and data from other internal services. This issue arises from improper validation of IPv6 Unique Local Addresses, which fails to block certain address ranges. Organizations using affected versions of draw.io, particularly those handling sensitive data or cloud infrastructure, should prioritize upgrading to version 30.3.8 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76898
Severity
HIGH
CVSS
7.7
EPSS
0.35%
Java

Original NVD Description

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.3.8, src/main/java/com/mxgraph/online/Utils.java checks IPv6 Unique Local Addresses in Utils.sanitizeUrl() by comparing the text prefixes fc00:: and fd00::, but the JDK returns the expanded address form, so the fc00::/7 range, including the AWS metadata range fd00:ec2::/32, is not blocked. An unauthenticated request to /embed2.js?fetch= can therefore make src/main/java/com/mxgraph/online/EmbedServlet2.java fetch an IPv6 ULA internal resource and reflect the response to the requester. Utils.validatedAddress() uses the same private-address check for the separate ProxyServlet path, which requires ENABLE_DRAWIO_PROXY=1. The primary /embed2.js path requires no proxy feature flag or DNS rebinding, and it can disclose cloud metadata credentials or data from other IPv6-reachable internal services. This issue is fixed in version 30.3.8.