Security Advisory

CVE-2026-72566

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-10 10:40:34
Last updated 2026-08-10 13:05:31
Assigner TuranSec
CVSS score not scored
State PUBLISHED

Description

A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticated user with 'manage Flow' permission to make the server fetch arbitrary URLs and retrieve the full response body via the HTTP Request app's Custom Request action.