Threats Tagged 'cve-2026-72598'
View all threats tagged with 'cve-2026-72598'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-72598'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-72598: CWE-918: Server-Side Request Forgery (SSRF) in Apioo FusioCVE-2026-72598 0 A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the server issue HTTP requests to internal network addresses by registering a webhook URL pointing to an internal host. The webhook registration endpoint validates URL syntax via FILTER_VALIDATE_URL but applies no IP or host denylist. When the registered event fires, the server issues an HTTP POST to the attacker-supplied internal URL. Join the discussion | CVE Database V5 | 08/11/2026, 11:14:02 UTC Added: 08/11/2026, 11:27:01 UTC |
Showing 1 to 1 of 1 result