PT-2026-43405 · Maxkb · Maxkb

·

CVE-2026-45412

·

Published

2026-05-26

·

Updated

2026-05-26

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MaxKB versions prior to 2.9.1
Description Authenticated users can perform Server-Side Request Forgery (SSRF) during the import of a work flow template. The application fetches arbitrary URLs provided in the downloadUrl variable of the work flow template without performing URL validation or internal IP filtering. SSRF is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location.
Recommendations Update to version 2.9.1.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45412
GHSA-X9G5-J56J-4MFJ

Affected Products

Maxkb