CVE-2026-76164: Authenticated Server-Side Request Forgery in AIL Framework Crawler Allows Access to Internal Network Resources

Published Aug 19, 2026
·
Updated

AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can submit an arbitrary URL for crawling without adequate validation of the destination host.

The crawler can therefore be instructed to make direct HTTP(S) requests to addresses that should not be reachable by application users, including loopback addresses, RFC1918 private networks, link-local addresses, and cloud metadata services such as 169.254.169.254.

Manual crawler tasks bypass the existing domain blacklist because they are assigned a non-zero priority, and ordinary IP literals are classified as web targets and fetched directly rather than through Tor or another proxy. Consequently, an attacker can use the AIL server as a network pivot to access services available from the server's network context.

Responses generated by these requests, including captured HTML, screenshots, and HAR data, can subsequently be accessed through the crawler interface. This makes the SSRF non-blind and may allow an attacker to disclose sensitive internal application data, service information, or cloud instance metadata and credentials.

The patch introduces validation that resolves crawler destinations and rejects URLs resolving to non-global IP addresses, addressing localhost, private-network, and link-local targets.

Affected Software

1 affected component
AIL Framework AIL Framework

Event History

Aug 19, 2026
CVE Published
via MITRE·08:53 AM
Data Sourced
via MITRE·08:53 AM
DescriptionWeakness

Frequently Asked Questions

1

Which users can exploit this issue?

A low-privileged authenticated user can exploit it if they have access to the crawler interface and can submit crawler tasks.

2

What systems could be reached from a vulnerable deployment?

The crawler can request loopback, RFC1918 private-network, link-local, and cloud metadata addresses, as well as other HTTP(S) services reachable from the AIL server’s network context.

3

Does the issue expose request results to the attacker?

Yes. Captured HTML, screenshots, and HAR data from crawler requests can be accessed through the crawler interface, making the SSRF non-blind.

4

Why do existing crawler controls not prevent the request?

Manual crawler tasks bypass the existing domain blacklist because they receive a non-zero priority. IP literals are also treated as web targets and fetched directly rather than through Tor or another proxy.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203