Server-Side Request Forgery in Automatisch Affected by Low-Privilege Authentication
CVE-2026-72566
7.7HIGH
What is CVE-2026-72566?
A server-side request forgery (SSRF) vulnerability has been identified in Automatisch. This flaw allows low-privileged authenticated users with 'manage Flow' permissions to exploit the server by making it fetch arbitrary URLs. Utilizing the HTTP Request app's Custom Request action, attackers can retrieve the full content of the response body from any accessible URL. This vulnerability raises significant security concerns by enabling unauthorized data access and potential exposure of internal resources.
Affected Version(s)
automatisch 0 <= 41f3c56
