PT-2026-85555 · Marqo Ai · Marqo

·

CVE-2026-85662

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Marqo 2.26.0 contains a server-side request forgery vulnerability in the add documents endpoint that allows unauthenticated attackers to trigger requests to arbitrary URLs by supplying malicious media field values. Attackers can exploit download image from url and fetch content sample functions which lack destination filtering and host validation to access internal services and cloud metadata endpoints.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85662

Affected Products

Marqo