Two server-side request forgery vulnerabilities were disclosed in widely deployed application servers, allowing attackers to use exposed systems to reach internal-only resources. Vikunja is affected by CVE-2026-33675, a medium-severity flaw with a CVSS v3.1 score of 6.4 that requires authentication but can let a user read data from services on the same internal network. Arcane is affected by CVE-2026-40242, a higher-severity issue scored 7.2 that requires no authentication and allows external attackers to send HTTP GET requests into internal network zones through the server’s template fetch mechanism.
The disclosures warn that both flaws can expose sensitive infrastructure that is normally unreachable from the internet, including cloud instance metadata endpoints, internal administrative interfaces, unauthenticated databases, Docker APIs, Redis services, and vulnerable microservices. In cloud environments, access to metadata services could reveal temporary IAM credentials, user-data scripts, and configuration variables that support lateral movement or privilege escalation. Arcane said the issue was patched in version 1.17.3 with tighter network boundaries, authentication checks, and sanitized error handling, while Vikunja’s flaw remains notable because it can undermine confidentiality even without directly enabling remote code execution.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A high-severity unauthenticated SSRF vulnerability in Arcane was publicly reported. The issue allows external attackers to relay HTTP GET requests into internal network zones, creating risk of internal service exposure and possible lateral movement.
Arcane addressed an unauthenticated SSRF vulnerability in version 1.17.3 by adding stricter network boundaries, explicit error sanitization, and authentication requirements. The flaw could let external attackers probe internal services such as Docker APIs, Redis, or cloud metadata endpoints.
A medium-severity server-side request forgery vulnerability affecting Vikunja task migration was disclosed. The flaw allows an authenticated attacker to access internal network resources reachable by the application server, with elevated risk in cloud environments due to possible metadata and credential exposure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.