CVE-2026-86173: MindsDB through 26.1.0 Unauthenticated SSRF via Web Crawler

Published Sep 5, 2026
·
Updated

MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can bypass the allowlist control by exploiting the default empty configuration and access internal services and cloud metadata endpoints without authentication.

Affected Software

1 affected component
MindsDB MindsDB<=26.1.0

Event History

Sep 5, 2026
CVE Published
via MITRE·11:01 AM
Data Sourced
via MITRE·11:01 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Any MindsDB deployment through version 26.1.0 that exposes the web crawler handler to network-reachable, unauthenticated users is exposed. The affected request path does not require authentication.

2

Does the default configuration prevent exploitation?

No. The allowlist can be bypassed because its default configuration is empty, allowing an attacker to supply arbitrary URLs to CrawlerTable.list.

3

What can an attacker access?

An attacker can cause the MindsDB server to fetch arbitrary URLs, including internal services and cloud metadata endpoints. The impact is unauthorized access to data reachable from the server's network context.

4

What can be done if patching is not immediately possible?

Restrict unauthenticated network access to the web crawler handler and prevent the MindsDB server from reaching sensitive internal services and cloud metadata endpoints. These measures reduce the ability to submit attacker-controlled URLs and limit what server-side requests can reach.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203