Server-Side Request Forgery in AIL Framework Crawler Submission Functionality
CVE-2026-76164
7.1HIGH
What is CVE-2026-76164?
The AIL Framework contains a vulnerability allowing authenticated low-privileged users to exploit the crawler submission functionality, enabling SSRF attacks. This flaw permits users to submit arbitrary URLs for crawling without sufficient validation, potentially accessing restricted network locations, including local and private addresses. Attackers can manipulate the crawler to make HTTP(S) requests to internal services, leading to possible disclosure of sensitive data, including internal application information and cloud metadata. With a recent patch, validations have been introduced to reject URLs linking to non-global IP addresses, thereby mitigating these potential exploits.
Affected Version(s)
ail-framework 0 < 7.0
