OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-88592

CRITICAL · CVSS 9.1 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

kkFileView versions 4.2.0 and above are susceptible to Server-Side Request Forgery (SSRF) due to a flaw in the TrustHostFilter validation mechanism. Attackers can exploit this vulnerability by manipulating request parameters to bypass security checks, allowing them to access and retrieve data from internal resources, which could lead to unauthorized information disclosure. Organizations using affected versions should prioritize remediation to mitigate potential data breaches and protect sensitive internal systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88592
Severity
CRITICAL
CVSS
9.1
EPSS
0.21%

Original NVD Description

kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFile is protected by TrustHostFilter against the trust.host whitelist. However, the URL parameter validated by the filter is not the same parameter the controller actually fetches: the filter validates the first non-empty parameter in a fixed priority order, while the controller only reads and fetches urlPath. By supplying both urlPath=<real target> and url=<whitelisted decoy address> in the same request, the decoy passes validation while the unvalidated real target is fetched server-side — and the response body is echoed back to the attacker.