Description
A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function IotDataSinkHttpConfig of the file /admin-api/iot/data-sink/create of the component Admin API Endpoint. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-05-25
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the YunaiV yudao‑cloud 2026.03 Admin API endpoint /admin-api/iot/data-sink/create exposes a Server‑Side Request Forgery flaw. By manipulating the IotDataSinkHttpConfig request, an attacker can trigger the server to issue outbound requests to arbitrary URLs, potentially accessing internal services or exfiltrating data. The flaw is triggered remotely, making it potentially exploitable from the internet and could lead to data disclosure or exploitation of internal resources.

Affected Systems

The affected product is YunaiV yudao‑cloud, version 2026.03. No other vendor or product versions are mentioned in the advisory.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation likelihood is unknown. However, because the flaw can be triggered remotely and the public has disclosed an exploit, the risk to networks that expose the vulnerable endpoint remains significant. Until a vendor patch is released, the principal mitigation is to restrict or monitor outbound traffic from this endpoint. The lack of vendor response increases the urgency to apply compensating controls.

Generated by OpenCVE AI on May 25, 2026 at 16:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • If an official patch or upgrade is available, apply it immediately.
  • Restrict outbound connections from the /admin-api/iot/data-sink/create endpoint to a whitelist of approved URLs or block the endpoint entirely for unauthenticated users.
  • Enable detailed logging for outbound requests and monitor logs for suspicious activity related to the SSRF endpoint.

Generated by OpenCVE AI on May 25, 2026 at 16:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 28 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 25 May 2026 14:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function IotDataSinkHttpConfig of the file /admin-api/iot/data-sink/create of the component Admin API Endpoint. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title YunaiV yudao-cloud Admin API Endpoint create IotDataSinkHttpConfig server-side request forgery
First Time appeared Yunaiv
Yunaiv yudao-cloud
Weaknesses CWE-918
CPEs cpe:2.3:a:yunaiv:yudao-cloud:*:*:*:*:*:*:*:*
Vendors & Products Yunaiv
Yunaiv yudao-cloud
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Yunaiv Yudao-cloud
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-28T17:29:02.038Z

Reserved: 2026-05-24T08:11:40.485Z

Link: CVE-2026-9464

cve-icon Vulnrichment

Updated: 2026-05-28T17:28:20.949Z

cve-icon NVD

Status : Deferred

Published: 2026-05-25T15:16:23.390

Modified: 2026-05-26T19:54:40.357

Link: CVE-2026-9464

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T17:45:31Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)