Server-Side Request Forgery in Automatisch Affected by Low-Privilege Authentication
CVE-2026-72566

7.7HIGH

Key Information:

Vendor
CVE Published:
10 August 2026

What is CVE-2026-72566?

A server-side request forgery (SSRF) vulnerability has been identified in Automatisch. This flaw allows low-privileged authenticated users with 'manage Flow' permissions to exploit the server by making it fetch arbitrary URLs. Utilizing the HTTP Request app's Custom Request action, attackers can retrieve the full content of the response body from any accessible URL. This vulnerability raises significant security concerns by enabling unauthorized data access and potential exposure of internal resources.

Affected Version(s)

automatisch 0 <= 41f3c56

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov
.