CVE-2026-76164: Authenticated Server-Side Request Forgery in AIL Framework Crawler Allows Access to Internal Network Resources
AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can submit an arbitrary URL for crawling without adequate validation of the destination host.
The crawler can therefore be instructed to make direct HTTP(S) requests to addresses that should not be reachable by application users, including loopback addresses, RFC1918 private networks, link-local addresses, and cloud metadata services such as 169.254.169.254.
Manual crawler tasks bypass the existing domain blacklist because they are assigned a non-zero priority, and ordinary IP literals are classified as web targets and fetched directly rather than through Tor or another proxy. Consequently, an attacker can use the AIL server as a network pivot to access services available from the server's network context.
Responses generated by these requests, including captured HTML, screenshots, and HAR data, can subsequently be accessed through the crawler interface. This makes the SSRF non-blind and may allow an attacker to disclose sensitive internal application data, service information, or cloud instance metadata and credentials.
The patch introduces validation that resolves crawler destinations and rejects URLs resolving to non-global IP addresses, addressing localhost, private-network, and link-local targets.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
A low-privileged authenticated user can exploit it if they have access to the crawler interface and can submit crawler tasks.
What systems could be reached from a vulnerable deployment?
The crawler can request loopback, RFC1918 private-network, link-local, and cloud metadata addresses, as well as other HTTP(S) services reachable from the AIL server’s network context.
Does the issue expose request results to the attacker?
Yes. Captured HTML, screenshots, and HAR data from crawler requests can be accessed through the crawler interface, making the SSRF non-blind.
Why do existing crawler controls not prevent the request?
Manual crawler tasks bypass the existing domain blacklist because they receive a non-zero priority. IP literals are also treated as web targets and fetched directly rather than through Tor or another proxy.