← All Advisories

CVE-2026-92566

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-92566

Key Details

CVECVE-2026-92566
CVSS Score / Version8.2 (High) / CVSS v3.1
Updated2026-09-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is low; availability impact is none.
Affected productsdatageartech datagear
Classified asCWE-918 (Server-Side Request Forgery (SSRF))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
datageartechdatagear
SubsystemsGeneral OT
SectorsMultiple

What to Know

DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI. Attackers can issue GET, POST, PUT, PATCH, or DELETE requests to internal endpoints and cloud metadata services, receiving full response bodies without authentication or validation. (NVD)

What to Do

Monitor datageartech's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-92566
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-92566