What is CVE-2026-72597?
CVE-2026-72597 is a Server-Side Request Forgery vulnerability in Friendica up to the 2026.08-dev branch, allowing authenticated users with free self-registered accounts to probe internal network services via the link-preview endpoint. The endpoint fetches any user-supplied URL without an internal IP deny list, so immediate patching is recommended.
Azərbaycanca: CVE-2026-72597, Friendica sosial şəbəkə platformasının 2026.08-dev filialına qədər olan versiyalarında autentifikasiya olunmuş istifadəçilərə Server-Side Request Forgery (SSRF) hücumu etməyə imkan verən boşluqdur. Pulsuz qeydiyyatlı hesab vasitəsilə link-preview funksiyası istismar edilərək daxili şəbəkə xidmətləri kəşf edilə bilər; dərhal yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What access level is required to exploit CVE-2026-72597?
An attacker must be an authenticated user on Friendica, but even a free self-registered account is sufficient to exploit this SSRF vulnerability.
Through which functionality is CVE-2026-72597 exploited?
The vulnerability is exploited through the link-preview endpoint, which fetches any user-supplied URL without an internal IP deny list, allowing internal network services to be probed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.