High severity8.5NVD Advisory· Published Apr 23, 2026· Updated Apr 29, 2026
CVE-2026-41461
CVE-2026-41461
Description
SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplied input passed via the uri request parameter is not sanitized before being used to construct outbound HTTP requests. Authenticated remote attackers can supply arbitrary URLs including internal network addresses and loopback addresses to cause the server to issue HTTP requests to attacker-controlled destinations, enabling internal network enumeration and access to services not intended to be externally reachable.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- karmainsecurity.com/KIS-2026-07nvdThird Party Advisory
- www.vulncheck.com/advisories/socialengine-blind-ssrf-via-core-link-previewnvdThird Party Advisory
- socialengine.comnvdProduct
- seclists.org/fulldisclosure/2026/Apr/11nvd
News mentions
0No linked articles in our index yet.