{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aprojeto_sigasiga/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:projeto_siga:siga:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-86273"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["siga (\u003c= 11.1.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["projeto-siga"],"content_html":"\u003cp\u003eA server-side request forgery (SSRF) vulnerability has been identified in projeto-siga siga, affecting all versions up to and including 11.1.1. The flaw resides within the HTML-to-PDF component, specifically in the DownloadExterno.getUrl function located in ExUtilController.java. An unauthenticated remote attacker can exploit this vulnerability by manipulating the 'html' argument to force the server to perform unauthorized HTTP requests. This capability can be leveraged to interact with internal network services that are otherwise inaccessible from the external perimeter, potentially leading to information disclosure or further exploitation of internal infrastructure. A proof-of-concept exploit for this vulnerability is currently publicly available, and the project maintainers have not yet provided a resolution for this issue.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-86273 allows remote, unauthenticated attackers to perform SSRF attacks against internal infrastructure. This can be used to bypass network access controls, perform internal service discovery, or exfiltrate sensitive data from internal systems that trust the siga application server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement egress filtering at the network level to restrict the siga application server from initiating connections to sensitive internal subnets, non-public IP ranges, or internal administration interfaces.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to inspect and sanitize the 'html' parameter in incoming requests targeting the DownloadExterno.getUrl endpoint for suspicious payloads.\u003c/li\u003e\n\u003cli\u003eMonitor web access logs for anomalous POST or GET requests to the identified controller path originating from external IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T06:50:54Z","date_published":"2026-09-07T06:50:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-86273/","summary":"The projeto-siga siga application is vulnerable to server-side request forgery (SSRF) via the DownloadExterno.getUrl function, allowing unauthenticated remote attackers to trigger unauthorized requests.","title":"SSRF Vulnerability in projeto-siga HTML-to-PDF Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-86273/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:projeto_siga:siga:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}