事件经过
NVD published (2026-10-02) a four-CVE cluster for the HAVELSAN Sef AI Chatbot Platform, sourced from the Turkish national CERT (siberguvenlik.gov.tr) security notification TR-26-1241, covering SQL injection (CVSS 8.8), man-in-the-middle via improper certificate validation (7.4), missing authorization (5.3), and SSRF (4.9). The vendor was contacted and confirmed the product is not supported, meaning no patches will be shipped.
影响分析
This is an AI chatbot platform shipped EOL with a full remote-attack surface (SQLi, SSRF, AiTM) and no remediation path. For any organization still running Sef, the only safe postures are isolation or migration; the SQLi and SSRF together could let an attacker reach backend data that the chatbot application proxies.
攻击途径
A set of four flaws disclosed via the Turkish national CERT bulletin TR-26-1241: SQL injection (CVE-2026-80298, CVSS 8.8); improper TLS certificate validation enabling adversarial-in-the-middle attacks (CVE-2026-80443); missing authorization letting users reach functionality not constrained by ACLs (CVE-2026-80337); and server-side request forgery (CVE-2026-80464)
受影响系统
HAVELSAN Inc. Sef AI Chatbot Platform before 2.1 (no longer supported by vendor)
缓解措施
No fixed release — the vendor stated the product is not supported. Immediately isolate or decommission exposed instances, place behind a WAF/reverse proxy, block outbound SSRF-prone requests, and disable TLS validation bypasses; plan migration off the EOL platform