CVE-2026-82081: SSRF
Published Aug 28, 2026
·Updated
wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.
Affected Software
1 affected component
wallabag wallabag>=2<=2.6.14
Event History
Aug 28, 2026
CVE Published
via MITRE·02:40 AM
Data Sourced
via MITRE·02:40 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The attacker needs low-level privileges. No user interaction is required for exploitation.
2
Can the issue be exploited remotely?
Yes. The attack vector is network-based and has low attack complexity.
3
What is the expected security impact?
The vulnerability can have low impact on confidentiality and integrity, with no availability impact indicated. Its scope is changed, meaning the impact can extend beyond the initially affected security authority.