Server-Side Request Forgery in Lightdash Affects Scheduled Delivery Webhook Functionality
CVE-2026-72846

5.3MEDIUM

Key Information:

Vendor

Lightdash

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-72846?

A vulnerability in Lightdash allows attackers to exploit unvalidated webhook URLs in scheduled deliveries, resulting in potential Server-Side Request Forgery (SSRF). The compromised functionality exposes internal services to attackers by enabling the delivery server to issue POST requests to any specified URL, including private and link-local addresses. This also allows attackers to infer the existence of internal services based on error messages while concealing responses from the original requester. To mitigate this risk, users are urged to upgrade to version 1.146.4, which implements URL validation for these webhook requests.

Affected Version(s)

lightdash 0 < 1.146.4

lightdash 1.146.4

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

geo-chen
.