CVE 6.3 MEDIUM

Huly Platform – Server-Side Request Forgery via /import Endpoint_CVE-2026-56769

6.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:L/SA:N

Description

Huly Platform before commit 68cbf8a contains an authenticated server-side request forgery vulnerability in the /import endpoint of front pod that allows workspace users to make arbitrary server requests. Attackers can exploit this by supplying malicious URLs to fetch internal services, exfiltrate responses, and replay credentials against backend systems.

Basic Information

ID CVE-2026-56769
Source VulnCheck
Published Jun 25, 2026 at 18:05

Affected Product

Vendor hcengineering
Product platform
Affected Versions hcengineering platform 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.