OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92931

HIGH · CVSS 8.8 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 is vulnerable to a Server-Side Request Forgery (SSRF) flaw, enabling remote attackers to send requests to malicious servers. This vulnerability could lead to the exposure of sensitive information from the affected systems. Organizations using these specific versions of the package should prioritize patching to mitigate the risk of data breaches.

CVE
CVE-2026-92931
Severity
HIGH
CVSS
8.8
EPSS
0.26%

Original NVD Description

CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.