ZDI-CAN-28215: ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability
Published Sep 16, 2026
·Updated
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92203.
Affected Software
1 affected component
Airbyte Airbyte SharePoint Connector
Event History
Sep 16, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker must authenticate to an affected Airbyte installation before exploiting the vulnerability.
2
What can a successful attacker do?
An authenticated remote attacker can cause the affected system to make arbitrary server-side requests, potentially disclosing information.
3
Which identifier should be used to track this vulnerability?
The assigned CVE identifier is CVE-2026-92203.