CVE-2026-41461 is a blind server-side request forgery vulnerability affecting SocialEngine versions 7.8.0 and prior in the /core/link/preview endpoint, where unsanitized user input via the uri parameter allows attackers to construct arbitrary outbound HTTP requests. Authenticated remote attackers can exploit this flaw to enumerate internal network addresses and access backend services not intended for external exposure. The attack requires authentication and a moderate level of complexity, as attackers must identify valid endpoints and interpret responses indirectly due to the blind SSRF nature. The vulnerability carries a FAUCET Risk Score of 44.0/100, indicating moderate concern; however, there is no formal CVSS rating, EPSS score, or inclusion in the Known Exploited Vulnerabilities catalog at this time. Exploitation appears limited, with the vulnerability currently inactive on public threat lists and no widespread evidence of active exploitation or public exploit availability, though the architectural flaw presents a legitimate risk for vulnerable deployments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 7.8.0CPE match | cpe:2.3:a:socialengine:socialengine:*:*:*:*:*:*:*:* | ||
<= 7.8.0CPE matchmatch criteria | cpe:2.3:a:socialengine:socialengine:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.