CVE-2026-55177
Received Received - Intake

Server-Side Request Forgery in CloudTAK

Vulnerability report for CVE-2026-55177, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to version 13.10.0, every route in the ESRI helper family (api/routes/esri.ts) takes a fully attacker-controlled URL from the request (POST /api/esri body url, and the portal / server / layer query parameters on the GET /api/esri/* routes) and passes it into EsriBase / EsriProxyPortal / EsriProxyServer / EsriProxyLayer in api/lib/esri.ts, which fetch it with the bare fetch from @tak-ps/etl. No IP / DNS / hostname classification is applied at any point, so the destination is never validated against private, loopback, or link-local ranges. Any authenticated user (the routes only require Auth.is_auth(config, req, { anyResources: true }), i.e. any token, not an admin) can therefore make the CloudTAK server issue arbitrary outbound GET/POST requests to internal addresses such as the cloud instance-metadata service (169.254.169.254), loopback admin ports (127.0.0.1:<port>), and other hosts reachable only from inside the deployment VPC. This is a full-read SSRF, not blind: on success the upstream JSON body is returned to the caller via res.json(...), and on failure the upstream error string is reflected verbatim as ESRI Server Error: <message>. An attacker can read cloud metadata (and the temporary IAM credentials the instance role exposes), enumerate internal services, and exfiltrate their response bodies. The sniff() URL classifier provides no protection: it only pattern-matches the pathname (/rest, /arcgis/rest, /sharing/rest), so a URL like http://169.254.169.254/arcgis/rest or http://127.0.0.1:8500/rest passes sniff() and is fetched. This issue has been patched in version 13.10.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
dfpc-coe cloudtak to 13.7.0 (inc)
dfpc-coe cloudtak 13.10.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55177 is an authenticated full-read Server-Side Request Forgery (SSRF) vulnerability in CloudTAK affecting versions up to 13.7.0. It allows authenticated users to make arbitrary outbound requests to internal addresses like cloud metadata services (169.254.169.254) or loopback ports (127.0.0.1:<port>) by exploiting the /api/esri* routes. The flaw exists because user-controlled URLs are fetched without IP or DNS validation.

Detection Guidance

Check CloudTAK logs for outbound requests to internal IP ranges (169.254.x.x, 127.0.0.1, RFC1918 ranges) from the /api/esri* routes. Monitor for repeated requests to metadata services or loopback ports. Use network traffic analysis tools to detect unauthorized outbound connections originating from the CloudTAK server.

Impact Analysis

An attacker can read cloud metadata, including temporary IAM credentials exposed by the instance role, enumerate internal services, and exfiltrate response bodies. This could lead to unauthorized access to sensitive data, privilege escalation, or further network compromise within the deployment VPC.

Compliance Impact

This vulnerability could violate compliance requirements by exposing sensitive data such as IAM credentials or internal service responses. GDPR may be impacted due to unauthorized data access, while HIPAA could be compromised if protected health information is exposed through internal service enumeration or exfiltration.

Mitigation Strategies

Upgrade CloudTAK to version 13.10.0 or later. Apply SSRF protection like isSafeUrl to all ESRI helper routes. Restrict network access to CloudTAK to prevent unauthorized outbound requests. Review and remove unnecessary user permissions that allow access to /api/esri* endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55177. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart