What is CVE-2026-47660?
In Pathling Server versions prior to 2.0.0, the 'bulk-submit' operation improperly validates an attacker-controlled `oauthMetadataUrl` parameter, potentially allowing an authorized submitter to exfiltrate data. Upgrading to Pathling Server version 2.0.0 is required to mitigate this issue.
Azərbaycanca: Pathling Server-in əvvəlki versiyalarında "bulk-submit" əməliyyatı "oauthMetadataUrl" parametrini kifayət qədər doğrulamır, bu da icazəli istifadəçilərə potensial olaraq arxa sistemə məlumat sızdırmaq imkanı yaradır. Pathling Server 2.0.0 versiyasına yüksəldilməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of Pathling Server are affected by CVE-2026-47660?
All versions of Pathling Server prior to 2.0.0 are affected by this vulnerability.
What is the mitigation for CVE-2026-47660?
Upgrading to Pathling Server version 2.0.0 is required to mitigate this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.