PatchSiren cyber security CVE debrief
CVE-2026-50775 DataHub CVE debrief
A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly. This vulnerability can lead to potential remote code execution via crafted URLs and SSRF attacks could lead to unauthorized access or data breaches. Defenders should prioritize verifying exposure of DataHub v1.5.0.1 to SSRF attacks and assess potential code execution risks due to the blind SSRF vulnerability.
- Vendor
- DataHub
- Product
- DataHub
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for DataHub deployments should assess potential exposure and risks associated with this vulnerability. Defenders should prioritize verifying exposure of DataHub v1.5.0.1 to SSRF attacks and assess potential code execution risks due to the blind SSRF vulnerability. Security teams and vulnerability management teams should review and assess the potential impact of this vulnerability on their DataHu
Why it matters
Defenders should prioritize verifying exposure of DataHub v1.5.0.1 to SSRF attacks and assess potential code execution risks due to the blind SSRF vulnerability.
- Potential remote code execution via crafted URLs
- SSRF attacks could lead to unauthorized access or data breaches
- Verify DataHub v1.5.0.1 deployment and assess exposure to SSRF attacks
Technical summary
The CVE description indicates a blind SSRF vulnerability in DataHub v1.5.0.1 that could lead to arbitrary code execution via a crafted URL. This vulnerability can lead to potential remote code execution via crafted URLs and SSRF attacks could lead to unauthorized access or data breaches. Defenders should prioritize verifying exposure of DataHub v1.5.0.1 to SSRF attacks and assess potential code execution risks.
Defensive priority
Defenders should prioritize verifying exposure of DataHub v1.5.0.1 to SSRF attacks and assess potential code execution risks.
Recommended defensive actions
- Verify DataHub v1.5.0.1 deployment and assess exposure to SSRF attacks
- Review server configurations for retrieving images from untrusted URLs
- Implement additional security controls to prevent code execution
Evidence notes
The CVE description indicates a blind SSRF vulnerability in DataHub v1.5.0.1 that could lead to arbitrary code execution. However, the description lacks specific details on exploitation or impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-50775 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-50775
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-50775 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-50775
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://datahub.com/
-
Source reference
Unverified legacy reference
URL: https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2026-50775
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.