Missing Authorization Flaw in HAVELSAN Inc. Sef AI Chatbot Platform
CVE-2026-80337

5.3MEDIUM

Key Information:

Vendor
CVE Published:
2 October 2026

What is CVE-2026-80337?

The Sef - AI Chatbot Platform from HAVELSAN Inc. exhibits a significant missing authorization vulnerability that allows unauthorized access to certain functionalities not adequately protected by Access Control Lists (ACLs). This flaw, present in versions prior to 2.1, poses serious security risks by circumventing the intended constraints designed to limit user access. Organizations using this platform should take immediate measures to mitigate risks associated with this vulnerability.

Affected Version(s)

Sef - AI Chatbot Platform 0 < 2.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Akıner KISA
.