CVE-2026-85662

Marqo 2.26.0 contains a server-side request forgery vulnerability in the add_documents endpoint that allows unauthenticated attackers to trigger requests to arbitrary URLs by supplying malicious media field values. Attackers can exploit download_image_from_url and fetch_content_sample functions which lack destination filtering and host validation to access internal services and cloud metadata endpoints.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 15:17

Updated : 2026-09-08 17:18


NVD link : CVE-2026-85662

Mitre link : CVE-2026-85662

CVE.ORG link : CVE-2026-85662


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)