<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cwe-918 — PoC Archive</title><link>https://poc.intelseclab.com/tags/cwe-918/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cwe-918/index.xml" rel="self" type="application/rss+xml"/><item><title>Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-08-09_cve-2026-64640-apache-polaris-cross-tenant-credential-vending/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-08-09_cve-2026-64640-apache-polaris-cross-tenant-credential-vending/</guid><description>High severity (CVSS 8.1) — cloud · CVE-2026-64640. Status: Patched. Affects: Apache Polaris (Apache Iceberg REST catalog), registerTable and registerView endpoints. Tags: apache-polaris, iceberg, apache-iceberg, credential-vending, confused-deputy, authorization-bypass, cross-tenant, s3, storage, allowed-locations, CWE-441, CWE-639, CWE-918, ssrf, server-side-read, information-disclosure, register-table, register-view.</description><category>cloud</category><category>High</category><category>apache-polaris</category><category>iceberg</category><category>apache-iceberg</category><category>credential-vending</category><category>confused-deputy</category><category>authorization-bypass</category><category>cross-tenant</category><category>s3</category><category>storage</category><category>allowed-locations</category><category>CWE-441</category><category>CWE-639</category><category>CWE-918</category><category>ssrf</category><category>server-side-read</category><category>information-disclosure</category><category>register-table</category><category>register-view</category></item><item><title>Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-19_cve-2026-20230-cisco-ucm-ssrf-arbitrary-file-write/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-19_cve-2026-20230-cisco-ucm-ssrf-arbitrary-file-write/</guid><description>Critical severity (CVSS 8.6) — network · CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW). Status: PoC — scanner/tester confirms the WebDialer precondition and SSRF reachability. Affects: Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME) — WebDialer service. Tags: cisco, unified-communications-manager, ucm, webdialer, ssrf, cwe-918, unauthenticated, remote, privilege-escalation, kev, actively-exploited.</description><category>network</category><category>Critical</category><category>cisco</category><category>unified-communications-manager</category><category>ucm</category><category>webdialer</category><category>ssrf</category><category>cwe-918</category><category>unauthenticated</category><category>remote</category><category>privilege-escalation</category><category>kev</category><category>actively-exploited</category></item><item><title>SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-15_cve-2026-15409-sonicwall-sma1000-ssrf-erlang-rce/</link><pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-15_cve-2026-15409-sonicwall-sma1000-ssrf-erlang-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-15409 (SNWLID-2026-0008). Status: Weaponized — unauthenticated, non-root remote code execution confirmed against a real appliance build. Affects: SonicWall SMA1000 Appliance — WorkPlace interface (websocket proxy service). Tags: sonicwall, sma1000, workplace, ssrf, erlang, rpc, cwe-918, unauthenticated, remote, kev, actively-exploited.</description><category>network</category><category>Critical</category><category>sonicwall</category><category>sma1000</category><category>workplace</category><category>ssrf</category><category>erlang</category><category>rpc</category><category>cwe-918</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>actively-exploited</category></item><item><title>ThingsBoard IoT Platform SSRF via SVG Image Upload (CVE-2025-34282)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-34282-thingsboard-ssrf-svg-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-34282-thingsboard-ssrf-svg-upload/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-34282. Status: Weaponized. Affects: ThingsBoard IoT Platform (Image Upload Gallery / Widget Library). Tags: thingsboard, ssrf, cwe-918, svg, image-upload, iot, python, widget-library, tenant-admin.</description><category>web</category><category>Critical</category><category>thingsboard</category><category>ssrf</category><category>cwe-918</category><category>svg</category><category>image-upload</category><category>iot</category><category>python</category><category>widget-library</category><category>tenant-admin</category></item><item><title>WordPress User Language Switch Plugin SSRF — CVE-2026-0745</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0745-uls-plugin-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0745-uls-plugin-ssrf/</guid><description>Medium severity — web · CVE-2026-0745 (GHSA-m38c-5p3m-p7gm). Status: PoC. Affects: WordPress "User Language Switch" plugin. Tags: wordpress, ssrf, plugin-vulnerability, admin-ajax, cwe-918, metadata-endpoint.</description><category>web</category><category>Medium</category><category>wordpress</category><category>ssrf</category><category>plugin-vulnerability</category><category>admin-ajax</category><category>cwe-918</category><category>metadata-endpoint</category></item><item><title>Unauthenticated SSRF in Ech0 via /api/website/title (CVE-2026-35037)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35037-ech0-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35037-ech0-ssrf/</guid><description>High severity — web · CVE-2026-35037. Status: PoC. Affects: lin-snow/Ech0. Tags: ssrf, ech0, unauthenticated, self-hosted, cwe-918, nuclei-template.</description><category>web</category><category>High</category><category>ssrf</category><category>ech0</category><category>unauthenticated</category><category>self-hosted</category><category>cwe-918</category><category>nuclei-template</category></item><item><title>Plunk SSRF via Unvalidated AWS SNS SubscriptionConfirmation — CVE-2026-32096</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-32096-plunk-sns-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-32096-plunk-sns-ssrf/</guid><description>Critical severity (CVSS 9.3) — cloud · CVE-2026-32096. Status: PoC. Affects: Plunk (useplunk/plunk) email/webhook API. Tags: ssrf, aws-sns, imds, cloud-metadata, plunk, cwe-918, unauthenticated.</description><category>cloud</category><category>Critical</category><category>ssrf</category><category>aws-sns</category><category>imds</category><category>cloud-metadata</category><category>plunk</category><category>cwe-918</category><category>unauthenticated</category></item><item><title>pdfmake Server-Side Request Forgery via Unvalidated Document URLs (CVE-2026-26801)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-26801-pdfmake-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-26801-pdfmake-ssrf/</guid><description>High severity — web · CVE-2026-26801. Status: Weaponized. Affects: pdfmake (Node.js PDF generation library), src/URLResolver.js. Tags: ssrf, pdfmake, node-js, cloud-metadata, aws-imds, cwe-918, credential-theft, data-exfiltration.</description><category>web</category><category>High</category><category>ssrf</category><category>pdfmake</category><category>node-js</category><category>cloud-metadata</category><category>aws-imds</category><category>cwe-918</category><category>credential-theft</category><category>data-exfiltration</category></item><item><title>Kan SSRF via Attachment Download Endpoint — CVE-2026-32255</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-32255-kan-ssrf-attachment-download/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-32255-kan-ssrf-attachment-download/</guid><description>High severity (CVSS 8.6) — web · CVE-2026-32255 (GHSA-qrx8-9hc6-jvqg). Status: PoC. Affects: Kan (kanbn/kan) open-source project management tool. Tags: ssrf, kan, project-management, cwe-918, cloud-metadata, unauthenticated, full-read-ssrf.</description><category>web</category><category>High</category><category>ssrf</category><category>kan</category><category>project-management</category><category>cwe-918</category><category>cloud-metadata</category><category>unauthenticated</category><category>full-read-ssrf</category></item><item><title>EspoCRM 9.3.3 Authenticated SSRF via Alternative IPv4 Loopback Notation — CVE-2026-33534</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33534-espocrm-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33534-espocrm-ssrf/</guid><description>Medium severity — web · CVE-2026-33534. Status: PoC. Affects: EspoCRM 9.3.3. Tags: espocrm, ssrf, cwe-918, ipv4-obfuscation, authenticated, crm, file-upload, python.</description><category>web</category><category>Medium</category><category>espocrm</category><category>ssrf</category><category>cwe-918</category><category>ipv4-obfuscation</category><category>authenticated</category><category>crm</category><category>file-upload</category><category>python</category></item><item><title>Chamilo LMS Unauthenticated install.ajax.php SSRF + Open Mail Relay — CVE-2026-33715</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33715-chamilo-lms-ssrf-mail-relay/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33715-chamilo-lms-ssrf-mail-relay/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-33715 / GHSA-mxc9-9335-45mc. Status: PoC. Affects: Chamilo LMS 2.0. Tags: ssrf, chamilo-lms, open-relay, unauthenticated, php, symfony-mailer, cwe-918, cwe-306, ajax-endpoint.</description><category>web</category><category>High</category><category>ssrf</category><category>chamilo-lms</category><category>open-relay</category><category>unauthenticated</category><category>php</category><category>symfony-mailer</category><category>cwe-918</category><category>cwe-306</category><category>ajax-endpoint</category></item><item><title>@haxtheweb/open-apis Credential Exposure via SSRF in cacheAddress Endpoint (CVE-2026-46391)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46391-haxtheweb-open-apis-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46391-haxtheweb-open-apis-ssrf/</guid><description>High severity — web · CVE-2026-46391 (GHSA-4fg7-f244-3j49). Status: PoC. Affects: @haxtheweb/open-apis (HAXcms/HAX ecosystem web service APIs). Tags: haxtheweb, haxcms, open-apis, ssrf, cwe-918, credential-exposure, cacheaddress.</description><category>web</category><category>High</category><category>haxtheweb</category><category>haxcms</category><category>open-apis</category><category>ssrf</category><category>cwe-918</category><category>credential-exposure</category><category>cacheaddress</category></item></channel></rss>