Server-Side Request Forgery Vulnerability in CloudTAK by DFPC
CVE-2026-55177
7.6HIGH
What is CVE-2026-55177?
CloudTAK, a browser-based situational awareness tool, is vulnerable to a Server-Side Request Forgery (SSRF). This flaw allows authenticated users to submit malicious URLs that fetch arbitrary internal resources from the CloudTAK server, potentially exposing sensitive internal services and cloud metadata, including temporary IAM credentials. Without IP or DNS validation, attackers can send requests to internal addresses, leading to data exfiltration. The vulnerability has been addressed in version 13.10.0.
Affected Version(s)
CloudTAK < 13.10.0
