CVE-2026-88403
Low
No strong exploitation signal.
CVSS base
—
EPSS — probability of exploitation (30 days)
—
CISA KEV
Not listed
Weakness / dates
—
Published 2026-09-21 · modified 2026-09-21
Description
A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.