ZDI-CAN-28216: ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability
Published Sep 16, 2026
·Updated
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92204.
Affected Software
1 affected component
Airbyte OneDrive Connector
Event History
Sep 16, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
Authentication is required. The issue is exploitable remotely by an authenticated attacker.
2
What can a successful attacker do?
A successful attacker can cause the affected Airbyte installation to make arbitrary server-side requests, which may result in information disclosure.