CVE-2026-80464: API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform
Published Oct 2, 2026
·Updated
Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery.
This issue affects Sef - AI Chatbot Platform: before 2.1.
Affected Software
1 affected component
HAVELSAN Sef - AI Chatbot Platform<2.1
Event History
Oct 2, 2026
CVE Published
via MITRE·08:58 AM
Data Sourced
via MITRE·08:58 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
HAVELSAN Sef - AI Chatbot Platform versions before 2.1 are affected.
2
What level of access does an attacker need?
The CVSS vector indicates that an attacker needs high privileges and can exploit the issue remotely without user interaction.
3
What is the expected impact of successful exploitation?
Successful exploitation can expose confidential information. The provided scoring indicates no integrity or availability impact.