Skip to content
High-Risk SSRF Vulnerability in Privoce VoceChat Server Disclosed

High-Risk SSRF Vulnerability in Privoce VoceChat Server Disclosed

First seen 28 Sep 2026, 06:32 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 07:36 UTC
  • •CVE-2026-100893 allows SSRF attacks on Privoce VoceChat Server up to version 0.5.36.
  • •The vulnerability is remotely exploitable without authentication, posing a high risk to internet-facing deployments.
  • •Mitigation strategies include restricting outbound traffic and monitoring application logs for suspicious URLs.

A critical vulnerability, CVE-2026-100893, has been identified in the Privoce VoceChat Server up to version 0.5.36. This vulnerability allows remote attackers to exploit the open_graph::fetch function by manipulating the URL parameter, leading to server-side request forgery (SSRF). The attack can be executed without authentication, making it accessible to any user with network access. The potential impact includes unauthorized access to internal services and cloud metadata, which could lead to further exploitation. The vendor was notified prior to the public disclosure but did not respond. Internet-facing deployments, particularly self-hosted chat servers, are at the highest risk. Mitigation steps include restricting outbound traffic and monitoring logs for unusual activity. The vulnerability was publicly disclosed on 2026-09-28.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-28
CVE-2026-100893 published
A vulnerability in Privoce VoceChat Server was disclosed, allowing SSRF attacks via unauthenticated requests.
Redpacketsecurity
2026-09-28
Public disclosure of SSRF vulnerability
The vulnerability was publicly disclosed after the vendor failed to respond to early notifications.
is.yuum.me

More articles in this cluster (3)

Following this threat?

Track Alibaba Cloud and CVE-2026-100893 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed