CVE-2026-6981 Details
Description
A vulnerability was found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. Affected is the function connect_stream_endpoint/sync_agents of the file AiraHub.py of the component Endpoint. Performing a manipulation results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.
A server-side request forgery (SSRF) vulnerability has been identified in IhateCreatingUserNames2 AiraHub2, specifically in the version 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. The vulnerability exists in the 'connect_stream_endpoint' and 'sync_agents' functions within the 'AiraHub.py' file, part of the Endpoint component. This issue allows remote attackers to manipulate user-controlled input, such as 'agent_url' and 'hub_urls', to coerce the server into making outbound HTTP requests. These requests can probe internal services or access cloud metadata endpoints, potentially leading to the exposure of sensitive information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 25, 2026CISA-ADP
Assessed Apr 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/wing3e/public_exp/issues/39 | [email protected] | ExploitIssue TrackingTechnical Analysis |
| https://vuldb.com/submit/795506 | [email protected] | Technical Description |
| https://vuldb.com/vuln/359524 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/vuln/359524/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| IhateCreatingUserNames2 AiraHub2 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 25, 2026 | New CVE Received | [email protected] |
Volerion