SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86122

MEDIUM · CVSS 5 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Rowboat versions prior to 0.9.1 are vulnerable due to inadequate validation of custom MCP server and webhook URLs, enabling authenticated users to redirect requests to arbitrary destinations. This flaw can lead to server-side request forgery (SSRF) attacks, allowing potential attackers to access internal services and enumerate the network topology. Organizations using Rowboat should prioritize remediation to mitigate risks associated with unauthorized access to sensitive internal resources.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86122
Severity
MEDIUM
CVSS
5
EPSS
0.23%

Original NVD Description

Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at internal services and cloud metadata endpoints to perform server-side request forgery and enumerate internal network topology.