CVE-2026-86115
Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation a
CVSS
5.0
Medium
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: Sep 5, 2026 · Last modified: Sep 5, 2026 · CWE-441
0.3%EPSS · 30 days0.3%
2026-09-062026-09-07
Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated workflow authors can bypass external URL validation by supplying paths starting with /api/ in HTTP blocks to reach internal-only endpoints like POST /api/function/execute.
- github.comhttps://github.com/geo-chen/oss/blob/main/sim.md
- github.comhttps://github.com/simstudioai/sim
- github.comhttps://github.com/simstudioai/sim/blob/v0.8.13/apps/sim/lib/auth/hybrid.ts
- github.comhttps://github.com/simstudioai/sim/blob/v0.8.13/apps/sim/tools/index.ts
- github.comhttps://github.com/simstudioai/sim/pull/7179
- www.vulncheck.comhttps://www.vulncheck.com/advisories/sim-before-0.8.14-confused-deputy-in-tool-url-routing-mints-an-internal-token-for-a-user-supplied-api-path
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-695315.5 MED—
———Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally.5hCVE-2026-866008.2 HIG—
———In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the driver to mint a fresh attestation and send it to a host they control. The captured token can be replayed to Snowflake for its remaining lifetime in accounts where that workload identity is already registered. On Azure, the token audience is also taken from connection configuration. Combined with an attacker-controlled host, the driver can request a Managed Identity access token scoped to a non-Snowflake Azure resource and deliver it to the attacker. That path is the only case in which impact extends beyond Snowflake; it is bounded by the token lifetime and the managed identity’s permissions. Successful exploitation requires WORKLOAD_IDENTITY authentication on a workload that already has an ambient cloud identity. Patched driver versions restrict this authenticator to recognized Snowflake hosts. Users must manually upgrade.5hCVE-2026-843295.3 MED6.5%
——2Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)5dCVE-2026-8354810.0 CRI51.2%
KEV—65SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability5dCVE-2026-773488.2 HIG15.8%
——5Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling cURL proxying (CURLOPT_PROXY = '' + CURLOPT_NOPROXY = '*'). However, Wallos ships a second, near-identical, unauthenticated logo-image search endpoint — endpoints/payments/search.php — that was not given the same hardening. It still passes the HTTP_PROXY/HTTPS_PROXY environment variable straight into CURLOPT_PROXY. This issue has been patched in version 5.0.0.5dCVE-2026-675679.9 CRI35.9%
——11A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the tenant to deploy arbitrary resources across the entire cluster, leading to a significant security compromise.11d