CVE-2026-92566
Last modified
CVE-2026-92566 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI. Attackers can issue GET, POST, PUT, PATCH, or DELETE requests to internal endpoints and cloud metadata services, receiving full response bodies without authentication or validation..
Description
DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI. Attackers can issue GET, POST, PUT, PATCH, or DELETE requests to internal endpoints and cloud metadata services, receiving full response bodies without authentication or validation.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| datageartech | datagear | <= 6.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-92566?
How severe is CVE-2026-92566?
How do I fix CVE-2026-92566?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-92527A vulnerability has been found in chatwoot up to 4.17.1. Thi…6.3
- CVE-2026-9253The WP Cost Estimation & Payment Forms Builder (E&P Forms) p…7.2
- CVE-2026-9254An unauthenticated OS command injection vulnerability exists…8.7
- CVE-2026-9255Missing input source validation in the tool authorization pr…8.4
- CVE-2026-9256NGINX Plus and NGINX Open Source have a vulnerability in the…8.1
- CVE-2026-92565Rallly before 4.15.0 contains an information disclosure vuln…5.3
- CVE-2026-92567TDuck survey form through version 5.0 contains an authorizat…6.5
- CVE-2026-92568MLRun through 1.11.0 contains a server-side request forgery …5.4
- CVE-2026-92569Hippo4j through 1.5.0 contains a server-side request forgery…4.3
- CVE-2026-92570reNgine through 2.2.0 contains an authorization bypass vulne…6.5
- CVE-2026-92571Rejected reason: CVE ID reserved in error and not assigned t…
- CVE-2026-92576HKUDS nanobot before 0.3.0 contains a server-side request fo…8.6
Are you affected by CVE-2026-92566?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
