CVE-2026-86173

MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can bypass the allowlist control by exploiting the default empty configuration and access internal services and cloud metadata endpoints without authentication.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-05 11:16

Updated : 2026-09-08 18:21


NVD link : CVE-2026-86173

Mitre link : CVE-2026-86173

CVE.ORG link : CVE-2026-86173


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)