CVE-2026-22681
Last modified
CVE-2026-22681 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a crafted URL to /api/v1/resources, causing the server to issue outbound HEAD and GET requests with redirects enabled to loopback, RFC 1918, link-local, or cloud metadata addresses, then read back responses through normal content APIs to enumerate and interact with internal services.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a crafted URL to /api/v1/resources, causing the server to issue outbound HEAD and GET requests with redirects enabled to loopback, RFC 1918, link-local, or cloud metadata addresses, then read back responses through normal content APIs to enumerate and interact with internal services.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Volcengine | OpenViking | < 0.3.4 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-22681?
How severe is CVE-2026-22681?
How do I fix CVE-2026-22681?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-22676Barracuda RMM versions prior to 2025.2.2 contain a privilege…8.5
- CVE-2026-22677Hermes WebUI prior to 0.51.44 contains a path traversal vuln…6.5
- CVE-2026-22678Webmin before 2.641 contains a stored cross-site scripting v…5.4
- CVE-2026-22679Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 con…9.8
- CVE-2026-2268The Ninja Forms plugin for WordPress is vulnerable to Sensit…7.5
- CVE-2026-22680OpenViking versions prior to 0.3.3 contain a missing authori…6.9
- CVE-2026-22682OpenHarness prior to commit 166fcfe contains an improper acc…8.4
- CVE-2026-22683Windmill versions 1.56.0 through 1.614.0 contain a missing a…8.8
- CVE-2026-22685DevToys is a desktop app for developers. In versions from 2.…9.8
- CVE-2026-22686Enclave is a secure JavaScript sandbox designed for safe AI …10
- CVE-2026-22687WeKnora is an LLM-powered framework designed for deep docume…9.8
- CVE-2026-22688WeKnora is an LLM-powered framework designed for deep docume…8.8
Are you affected by CVE-2026-22681?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
