CVE-2026-72566: automatisch - Server-Side Request Forgery via HTTP Request Custom Action
Published Aug 10, 2026
·Updated
A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticated user with 'manage Flow' permission to make the server fetch arbitrary URLs and retrieve the full response body via the HTTP Request app's Custom Request action.
Affected Software
1 affected component
automatisch>undefined
Event History
Aug 10, 2026
CVE Published
via MITRE·10:40 AM
Data Sourced
via MITRE·10:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-72566?
The severity of CVE-2026-72566 is rated high with a score of 7.7.
2
What type of vulnerability is CVE-2026-72566?
CVE-2026-72566 is a Server-Side Request Forgery (SSRF) vulnerability.
3
How do I fix CVE-2026-72566?
To fix CVE-2026-72566, ensure that proper input validation and permission checks are implemented for HTTP requests.
4
Who is affected by CVE-2026-72566?
CVE-2026-72566 affects low-privileged authenticated users with 'manage Flow' permission in automatisch.
5
What can attackers do with CVE-2026-72566?
Attackers can exploit CVE-2026-72566 to make the server fetch arbitrary URLs and retrieve their full response.