ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability
Published Sep 16, 2026
·Updated
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92203.
Affected Software
1 affected component
Airbyte
Event History
Sep 16, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated to the affected Airbyte installation. The provided information does not identify any further privilege requirements.
2
What can a successful attacker do?
A successful attacker can cause the affected installation to make arbitrary server-side requests, which can disclose information reachable from the server. The issue has a CVSS rating of 7.7.