medium · CVSS v3 4.9 · EPSS 0.00274
CVE-2026-80464
The CVE-2026-80464 vulnerability is a server‑side request forgery (SSRF) flaw in HAVELSAN Inc. Sef – AI Chatbot Platform versions prior to 2
Overview
The CVE-2026-80464 vulnerability is a server‑side request forgery (SSRF) flaw in HAVELSAN Inc. Sef – AI Chatbot Platform versions prior to 2.1. It allows attackers to force the server to make arbitrary HTTP requests, potentially exposing internal resources or exfiltrating data.
Description
Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.
Impact
SSRF can lead to unauthorized data disclosure, internal network reconnaissance, or execution of internal services. The confidentiality of internal endpoints may be compromised, integrity of data could be altered if the platform interacts with writable services, and availability may be impacted if the platform is overloaded with forged requests. Defenders are primarily the system administrators and security teams managing the chatbot deployment.
Remediation
Because the product is no longer supported, apply the following mitigations: block outbound traffic from the chatbot server to untrusted networks using firewall rules; enable strict outbound request whitelisting; disable or restrict any features that allow external URL input; monitor logs for anomalous outbound requests; consider migrating to a supported platform.
Risk context
With a medium severity score of 4.9 and an EPSS of 0.00274, the likelihood of exploitation is low but the impact can be significant if the chatbot is exposed to the internet. Defenders should treat this as a low‑to‑moderate risk but still implement mitigations promptly.
Affected products
- HAVELSAN Sef AI Chatbot Platform
Scores
- Severity
- medium
- CVSS v2
- 6.1
- CVSS v3
- 4.9
- CVSS v4
- —
- EPSS
- 0.00274