rootpwn

medium · CVSS v3 4.9 · EPSS 0.00274

CVE-2026-80464

The CVE-2026-80464 vulnerability is a server‑side request forgery (SSRF) flaw in HAVELSAN Inc. Sef – AI Chatbot Platform versions prior to 2

Overview

The CVE-2026-80464 vulnerability is a server‑side request forgery (SSRF) flaw in HAVELSAN Inc. Sef – AI Chatbot Platform versions prior to 2.1. It allows attackers to force the server to make arbitrary HTTP requests, potentially exposing internal resources or exfiltrating data.

Description

Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.

Impact

SSRF can lead to unauthorized data disclosure, internal network reconnaissance, or execution of internal services. The confidentiality of internal endpoints may be compromised, integrity of data could be altered if the platform interacts with writable services, and availability may be impacted if the platform is overloaded with forged requests. Defenders are primarily the system administrators and security teams managing the chatbot deployment.

Remediation

Because the product is no longer supported, apply the following mitigations: block outbound traffic from the chatbot server to untrusted networks using firewall rules; enable strict outbound request whitelisting; disable or restrict any features that allow external URL input; monitor logs for anomalous outbound requests; consider migrating to a supported platform.

Risk context

With a medium severity score of 4.9 and an EPSS of 0.00274, the likelihood of exploitation is low but the impact can be significant if the chatbot is exposed to the internet. Defenders should treat this as a low‑to‑moderate risk but still implement mitigations promptly.

Affected products

  • HAVELSAN Sef AI Chatbot Platform

Scores

Severity
medium
CVSS v2
6.1
CVSS v3
4.9
CVSS v4
—
EPSS
0.00274

SSRF HAVELSAN AI Chatbot Server‑Side Request Forgery Unsupported Mitigation Network Restriction

← All CVEs