SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86539

HIGH · CVSS 7.2 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A server-side request forgery vulnerability exists in the POST /api/embedding-models/test endpoint of the affected product, allowing attackers to send requests to arbitrary destinations without proper validation. This can lead to the enumeration of internal hosts and exposure of sensitive cloud metadata through transport error messages that disclose network reachability. Organizations utilizing this product should prioritize remediation to mitigate the risk of internal network exposure and potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86539
Severity
HIGH
CVSS
7.2
EPSS
0.21%

Original NVD Description

knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.