CVE-2026-102138
Received Received - Intake

Authenticated Connector URL Requests in Gateway Role

Vulnerability report for CVE-2026-102138, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

An authenticated administrator on a node with an optional, separately licensed gateway role enabled could supply a connector URL that the server retrieved without sufficient validation of its scheme or destination, causing the server to issue requests to internal network services. Exploitation requires the licensed gateway role to be active.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated administrator with a specific licensed gateway role to provide a connector URL that the server accesses without proper validation of the URL's scheme or destination. This could let the server make requests to internal network services.

Impact Analysis

An attacker with admin access and the gateway role could exploit this to access internal services, potentially leading to data breaches, unauthorized actions, or network reconnaissance.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to internal systems, potentially exposing sensitive data and violating data protection regulations like GDPR or HIPAA.

Mitigation Strategies

Disable the licensed gateway role if not actively used. Ensure strict validation of connector URLs by the server to prevent internal network requests. Restrict administrative access to only trusted users.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102138. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart