Server-side Request Forgery Vulnerability in Marqo 2.26.0
CVE-2026-85662

6.9MEDIUM

Key Information:

Vendor

Marqo-ai

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85662?

The Marqo version 2.26.0 is susceptible to a server-side request forgery (SSRF) vulnerability within the add_documents endpoint. Unauthenticated attackers can manipulate the media field values to initiate requests to arbitrary URLs. By exploiting the inadequate filtering and lack of host validation in the download_image_from_url and fetch_content_sample functions, attackers can potentially access internal services and cloud metadata endpoints, leading to unauthorized data exposure.

Affected Version(s)

marqo 0 <= 2.26.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.