CVE-2026-102145
Received Received - Intake

Authenticated Server-Side Request Forgery in Web Application

Vulnerability report for CVE-2026-102145, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-93 The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated administrator to make the server send requests to internal network services that should not be accessible through this interface. While it does not directly allow code execution, it could enable unauthorized interaction with internal systems.

Impact Analysis

An attacker with admin access could exploit this to probe or interact with internal services, potentially leading to data breaches, unauthorized access to sensitive systems, or further exploitation of internal network weaknesses.

Compliance Impact

This vulnerability could violate compliance requirements by exposing internal systems to unauthorized access, potentially leading to data leaks or unauthorized processing of personal or sensitive data, which is prohibited under standards like GDPR and HIPAA.

Mitigation Strategies

Restrict access to the server interface to only trusted networks or IP addresses. Review and update firewall rules to prevent unauthorized internal network requests. Monitor server logs for unusual outbound requests to internal services.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102145. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart