HAVELSAN公司Sef人工智能聊天平台存在权限缺失漏洞,该漏洞使得系统功能访问缺乏访问控制列表(ACL)的有效约束,导致用户可访问未适当限制的功能。 受影响产品:Sef AI聊天平台;影响版本:2.1之前的所有版本
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HAVELSAN Inc. | Sef - AI Chatbot Platform | 0 ~ 2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80298 | 8.8 HIGH | SQL Injection in HAVELSAN's Sef - AI Chatbot Platform |
| CVE-2026-80443 | 7.4 HIGH | Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI Chatbot Pla |
| CVE-2026-80464 | 4.9 MEDIUM | API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform |
No comments yet