CVE-2026-80464: medium-severity vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform
API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.9epss 0.3%
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery.
This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected products
HAVELSAN Inc. · Sef - AI Chatbot PlatformRelated CVEs — HAVELSAN Inc. Sef - AI Chatbot Platform
In the same product, most dangerous first.
CVE-2026-80298HIGHSQL Injection in HAVELSAN's Sef - AI Chatbot PlatformEPSS 0.3%CVE-2026-80337MEDIUMUnauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot PlatformEPSS 0.2%CVE-2026-80443HIGHInsecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI Chatbot PlatformEPSS 0.2%