ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability
Published Sep 16, 2026
·Updated
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92204.
Affected Software
1 affected component
Airbyte OneDrive Connector
Event History
Sep 16, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker who is authenticated to an affected Airbyte installation can exploit it. The provided information does not identify any additional privilege requirements.
2
What can successful exploitation allow?
Successful exploitation allows the attacker to cause the affected server to initiate arbitrary server-side requests, which can expose information reachable from that server.
3
How severe is the vulnerability?
ZDI assigned a CVSS rating of 7.7. The advisory identifies the issue as CVE-2026-92204.