rootpwn

medium · CVSS v3 5.3 · EPSS 0.0021

CVE-2026-80337

CVE-2026-80337 is a missing authorization flaw in HAVELSAN Inc. Sef – AI Chatbot Platform that allows unauthorized users to access restricte

Overview

CVE-2026-80337 is a missing authorization flaw in HAVELSAN Inc. Sef – AI Chatbot Platform that allows unauthorized users to access restricted functionality. The vulnerability exists in all versions prior to 2.1 and could enable attackers to perform privileged actions without proper ACL checks.

Description

Missing Authorization vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.

Impact

Confidentiality: attackers could read or modify data processed by the chatbot. Integrity: unauthorized changes to chatbot configuration or data. Availability: potential for denial of service by abusing privileged functions. Defenders: system administrators and security teams managing the platform.

Remediation

Upgrade to a supported version or replace the platform. Apply network segmentation to isolate the chatbot. Enforce strict ACLs and monitor for unauthorized access. If upgrade is not possible, restrict API access and require authentication.

Risk context

The CVE has a medium severity score of 5.3 and a very low EPSS of 0.0021, indicating a low likelihood of exploitation in the wild. However, the missing authorization could still be leveraged by determined adversaries, so defenders should assess exposure promptly.

Affected products

  • HAVELSAN Sef AI Chatbot

Scores

Severity
medium
CVSS v2
4.9
CVSS v3
5.3
CVSS v4
—
EPSS
0.0021

missing-authorization ACL AI-chatbot HAVELSAN medium-severity low-epss

← All CVEs