CVE-2026-77112: SSRF Leading to JWT Token Disclosure in Global IT Informatics' Weoll
Published Sep 23, 2026
·Updated
Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server Side Request Forgery.
This issue affects Weoll: before 3.2.45.44.
Affected Software
1 affected component
Global IT Informatics Technology Services Weoll<3.2.45.44
Event History
Sep 23, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require authentication or local access?
No privileges or local access are required according to the CVSS vector. The attack is network-based, has low attack complexity, and requires user interaction.
2
What impact is indicated if the issue is exploited?
The recorded impact is high confidentiality impact, with no integrity or availability impact indicated. The vulnerability is rated medium severity with a CVSS score of 6.5.