Server-Side Request Forgery Vulnerability in Apioo Fusio by Apioo
CVE-2026-72598

6.5MEDIUM

Key Information:

Vendor

Apioo

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72598?

A server-side request forgery vulnerability exists in Apioo Fusio version 8.8.3, which allows authenticated users with consumer roles to exploit webhook functionality. By registering an internal host URL within a webhook registration endpoint that inadequately validates the host against a denylist, attackers can trigger unauthorized HTTP requests to internal network addresses. This oversight enables potential information disclosure and further attacks on internal systems.

Affected Version(s)

Fusio 0 <= 8.8.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov
.