What is CVE-2026-19927?
A server-side request forgery (SSRF) vulnerability was discovered in OpenBoxes up to version 0.9.7, affecting the 'Product Upload Endpoint' in the ProductController.groovy file. Manipulating the 'params.url' argument could allow remote code execution or internal network access. Users should immediately update to the latest version or apply security patches.
Azərbaycanca: OpenBoxes 0.9.7 və əvvəlki versiyalarında 'Product Upload Endpoint' komponentində server-side request forgery (SSRF) zəifliyi aşkar edilib. Bu, 'params.url' arqumentinin manipulyasiyası vasitəsilə uzaqdan kod icrasına və ya daxili şəbəkəyə girişə imkan verə bilər. İstifadəçilərə dərhal son versiyaya yeniləmə və ya təhlükəsizlik yamalarını tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of OpenBoxes are affected by the CVE-2026-19927 SSRF vulnerability?
The vulnerability affects OpenBoxes up to version 0.9.7, including all prior releases.
What can an attacker achieve by exploiting the CVE-2026-19927 vulnerability?
By manipulating the 'params.url' argument, an attacker can achieve remote code execution or gain access to internal networks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.