{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/dradis/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-79788"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Dradis Community Edition"],"_cs_severities":["high"],"_cs_tags":["web-application","ssrf","vulnerability","authorization-bypass"],"_cs_type":"advisory","_cs_vendors":["Dradis"],"content_html":"\u003cp\u003eDradis Community Edition contains an authorization bypass vulnerability (CVE-2026-79788) within the ProvidersController and AgentsController. The application improperly gates the \u003ccode\u003eadmin_required\u003c/code\u003e before_action by checking for the \u003ccode\u003eDradis::Pro\u003c/code\u003e constant, which is never defined in the Community Edition. This failure causes the authorization check to be skipped entirely, allowing any authenticated, non-privileged user to modify AI provider and agent configurations. Attackers can leverage this to create malicious AI providers that point to internal or cloud-local network addresses, including metadata services such as 169.254.169.254. When an AI interaction is subsequently triggered, the application performs an outbound request to the attacker-defined URL. Because the application reflects response bodies of non-2xx status codes via ActionCable/Turbo Stream, an attacker can read the content of internal network resources, leading to potential data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users to perform server-side request forgery against internal resources or cloud metadata services. This can result in unauthorized access to sensitive internal configuration data, cloud environment credentials, or metadata, facilitating deeper compromise of the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server and application logs for unexpected outbound connections from the Dradis server, particularly to private IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, and 169.254.169.254).\u003c/li\u003e\n\u003cli\u003eReview access logs for non-administrative users interacting with the \u003ccode\u003e/providers\u003c/code\u003e and \u003ccode\u003e/agents\u003c/code\u003e controller endpoints.\u003c/li\u003e\n\u003cli\u003eApply security patches or updates provided by the vendor to address CVE-2026-79788.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering at the network level to restrict the Dradis server from initiating requests to internal or metadata-related IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T20:49:31Z","date_published":"2026-08-25T20:49:31Z","id":"https://feed.craftedsignal.io/briefs/2026-08-dradis-ssrf/","summary":"An authorization bypass vulnerability in Dradis Community Edition allows authenticated users to execute SSRF attacks by injecting malicious AI provider configurations.","title":"Authorization Bypass and SSRF in Dradis Community Edition","url":"https://feed.craftedsignal.io/briefs/2026-08-dradis-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Dradis","version":"https://jsonfeed.org/version/1.1"}