medium · CVSS v3 5.3 · EPSS 0.0021
CVE-2026-80337
CVE-2026-80337 is a missing authorization flaw in HAVELSAN Inc. Sef – AI Chatbot Platform that allows unauthorized users to access restricte
Overview
CVE-2026-80337 is a missing authorization flaw in HAVELSAN Inc. Sef – AI Chatbot Platform that allows unauthorized users to access restricted functionality. The vulnerability exists in all versions prior to 2.1 and could enable attackers to perform privileged actions without proper ACL checks.
Description
Missing Authorization vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.
Impact
Confidentiality: attackers could read or modify data processed by the chatbot. Integrity: unauthorized changes to chatbot configuration or data. Availability: potential for denial of service by abusing privileged functions. Defenders: system administrators and security teams managing the platform.
Remediation
Upgrade to a supported version or replace the platform. Apply network segmentation to isolate the chatbot. Enforce strict ACLs and monitor for unauthorized access. If upgrade is not possible, restrict API access and require authentication.
Risk context
The CVE has a medium severity score of 5.3 and a very low EPSS of 0.0021, indicating a low likelihood of exploitation in the wild. However, the missing authorization could still be leveraged by determined adversaries, so defenders should assess exposure promptly.
Affected products
- HAVELSAN Sef AI Chatbot
Scores
- Severity
- medium
- CVSS v2
- 4.9
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- 0.0021