Vulnerability  ·  2026-10-04

HAVELSAN Sef AI Chatbot Platform: cluster of SQL injection, AiTM cert-validation, broken ACL and SSRF flaws in unsupported product (CVE-2026-80298, CVE-2026-80443, CVE-2026-80337, CVE-2026-80464)

VulnerabilityHigh impactGlobalCVE-2026-80298
NVD published (2026-10-02) a four-CVE cluster for the HAVELSAN Sef AI Chatbot Platform, sourced from the Turkish national CERT (siberguvenlik.gov.tr) security notification TR-26-1241, covering SQL injection (CVSS 8.8), man-in-the-middle via improper certificate validation (7.4), missing authorization (5.3), and SSRF (4.9). The vendor was contacted and confirmed the product is not supported, meaning no patches will be shipped.
This is an AI chatbot platform shipped EOL with a full remote-attack surface (SQLi, SSRF, AiTM) and no remediation path. For any organization still running Sef, the only safe postures are isolation or migration; the SQLi and SSRF together could let an attacker reach backend data that the chatbot application proxies.
A set of four flaws disclosed via the Turkish national CERT bulletin TR-26-1241: SQL injection (CVE-2026-80298, CVSS 8.8); improper TLS certificate validation enabling adversarial-in-the-middle attacks (CVE-2026-80443); missing authorization letting users reach functionality not constrained by ACLs (CVE-2026-80337); and server-side request forgery (CVE-2026-80464)
HAVELSAN Inc. Sef AI Chatbot Platform before 2.1 (no longer supported by vendor)
No fixed release — the vendor stated the product is not supported. Immediately isolate or decommission exposed instances, place behind a WAF/reverse proxy, block outbound SSRF-prone requests, and disable TLS validation bypasses; plan migration off the EOL platform
NVD: CVE-2026-80298 (Sef AI Chatbot Platform SQL injection)TR-CERT bulletin tr-26-1241
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →