漏洞  ·  2026-10-04

HAVELSAN Sef AI Chatbot Platform: cluster of SQL injection, AiTM cert-validation, broken ACL and SSRF flaws in unsupported product (CVE-2026-80298, CVE-2026-80443, CVE-2026-80337, CVE-2026-80464)

漏洞High 影响GlobalCVE-2026-80298
NVD published (2026-10-02) a four-CVE cluster for the HAVELSAN Sef AI Chatbot Platform, sourced from the Turkish national CERT (siberguvenlik.gov.tr) security notification TR-26-1241, covering SQL injection (CVSS 8.8), man-in-the-middle via improper certificate validation (7.4), missing authorization (5.3), and SSRF (4.9). The vendor was contacted and confirmed the product is not supported, meaning no patches will be shipped.
This is an AI chatbot platform shipped EOL with a full remote-attack surface (SQLi, SSRF, AiTM) and no remediation path. For any organization still running Sef, the only safe postures are isolation or migration; the SQLi and SSRF together could let an attacker reach backend data that the chatbot application proxies.
A set of four flaws disclosed via the Turkish national CERT bulletin TR-26-1241: SQL injection (CVE-2026-80298, CVSS 8.8); improper TLS certificate validation enabling adversarial-in-the-middle attacks (CVE-2026-80443); missing authorization letting users reach functionality not constrained by ACLs (CVE-2026-80337); and server-side request forgery (CVE-2026-80464)
HAVELSAN Inc. Sef AI Chatbot Platform before 2.1 (no longer supported by vendor)
No fixed release — the vendor stated the product is not supported. Immediately isolate or decommission exposed instances, place behind a WAF/reverse proxy, block outbound SSRF-prone requests, and disable TLS validation bypasses; plan migration off the EOL platform
NVD: CVE-2026-80298 (Sef AI Chatbot Platform SQL injection)TR-CERT bulletin tr-26-1241
在实时动态中查看 浏览更多 AI 安全与治理相关发现 — 每日清晨更新。
打开动态 →