CRITICAL
9.1 CVE-2026-88592 Published 16 Sept 2026
kkFileView SSRF Vulnerability
Worried this affects your website?
kkFileView versions 4.2.0 and later are affected by a Server-Side Request Forgery (SSRF) vulnerability.
The /getCorsFile endpoint is supposed to be protected by TrustHostFilter, but the filter validates a different parameter than the one used by the controller, leading to unauthorized access.
Reference: CVE-2026-88592 on NVD
← Back to Security News