CRITICAL 9.1 CVE-2026-88592 Published 16 Sept 2026

kkFileView SSRF Vulnerability

Worried this affects your website?

kkFileView versions 4.2.0 and later are affected by a Server-Side Request Forgery (SSRF) vulnerability.

The /getCorsFile endpoint is supposed to be protected by TrustHostFilter, but the filter validates a different parameter than the one used by the controller, leading to unauthorized access.

Reference: CVE-2026-88592 on NVD

← Back to Security News