CVE-2026-80337: Unauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot Platform
Published Oct 2, 2026
·Updated
Missing Authorization vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Sef - AI Chatbot Platform: before 2.1.
Affected Software
1 affected component
HAVELSAN Sef - AI Chatbot Platform<2.1
Event History
Oct 2, 2026
CVE Published
via MITRE·09:01 AM
Data Sourced
via MITRE·09:01 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
HAVELSAN Sef - AI Chatbot Platform versions before 2.1 are affected.
2
What level of access does an attacker need?
The vulnerability requires low-level privileges. It is remotely exploitable, does not require user interaction, and has high confidentiality impact.
3
What is the exploitation complexity?
Exploitation is rated as high complexity. The available data does not identify the specific conditions or steps needed to invoke another chatbot's tools.