Description
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-08-03
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a server‑side request forgery (SSRF) in Microsoft Edge (Chromium‑based). An attacker who can supply a malicious URL to the browser can cause Edge to send requests to internal or otherwise restricted network resources, effectively enabling spoofing and potentially allowing the attacker to impersonate trusted services or exfiltrate data. The vulnerability, classified as CWE‑918, could compromise confidentiality and integrity of internal systems if no safeguards are in place.

Affected Systems

Microsoft Edge (Chromium‑based) is affected. No specific edition or version ranges are listed in the available data; all installations of Microsoft Edge (Chromium‑based) should be considered potentially vulnerable until further vendor guidance is released.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity. No EPSS score is available, and the vulnerability is not yet listed in CISA’s KEV catalog, suggesting that widespread exploitation has not been observed. The most likely attack vector is through a malicious web page that the user visits, leveraging the browser to send forged requests. The absence of an official exploit reference further points to a low to moderate exploitation probability under current conditions.

Generated by OpenCVE AI on August 4, 2026 at 20:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version or apply the security update available from Microsoft’s update guide.
  • Restrict Edge’s outbound connectivity to internal networks by configuring local firewall rules or group policy settings until the patch is deployed.
  • Monitor browser logs for suspicious internal requests.

Generated by OpenCVE AI on August 4, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-20T17:06:41.668Z

Reserved: 2026-07-24T18:06:51.296Z

Link: CVE-2026-66325

cve-icon Vulnrichment

Updated: 2026-08-04T14:19:45.462Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T00:17:39.703

Modified: 2026-08-06T17:09:25.940

Link: CVE-2026-66325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)