Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisory

SocialEngine Blind SSRF in `/core/link/preview` Fixed in Version 8.0.0

Updated 28d agoFirst seen Apr 29, 20262 sources

A public advisory disclosed CVE-2026-41461, a blind server-side request forgery flaw in SocialEngine affecting 7.8.0, 7.7.0, and likely earlier versions. The vulnerability stems from improper sanitization of the uri parameter in the /core/link/preview endpoint, allowing an authenticated remote attacker to make the SocialEngine server issue HTTP requests to internal or arbitrary destinations, including localhost-accessible services. The issue was discovered by Egidio Romano.

The vendor was notified in February 2026, but the flaw remained present in SocialEngine 7.8.0 and no official fix was available at the time of public disclosure after the 60-day window. SocialEngine later released version 8.0.0, and the researcher confirmed that release properly remediated the SSRF issue. The disclosure indicates the bug could be abused for internal network reachability and server-side request pivoting from authenticated accounts.

Share:
SocialEngine Blind SSRF in `/core/link/preview` Fixed in Version 8.0.0
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
May 19, 20261mo ago

Reporter confirms SocialEngine 8.0.0 fixes CVE-2026-41461

On verification, Egidio Romano confirmed that SocialEngine 8.0.0 properly remediated the blind SSRF vulnerability tracked as CVE-2026-41461.

May 15, 20261mo ago

SocialEngine 8.0.0 is released

SocialEngine released version 8.0.0 following the public disclosure of the SSRF issue. This release was later confirmed by the reporter to address the vulnerability.

Apr 23, 20262mo ago

Blind SSRF vulnerability in SocialEngine is publicly disclosed

After the 60-day disclosure window, the SSRF issue was publicly disclosed, with no official patch or workaround available at that time. The advisory said authenticated attackers could force the server to send requests to internal or arbitrary destinations.

Feb 27, 20264mo ago

SocialEngine 7.8.0 releases without fixing the SSRF flaw

SocialEngine released version 7.8.0, but the blind SSRF vulnerability remained present. The flaw involved insufficient sanitization of the /core/link/preview endpoint's uri parameter.

Feb 2, 20265mo ago

Researcher notifies SocialEngine of SSRF vulnerability

Egidio Romano reported a blind server-side request forgery flaw in SocialEngine to the vendor. The issue affected version 7.7.0, likely earlier releases, and was later assigned CVE-2026-41461.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

4 LINKEDOpen in app
Affected products
1 linked
Socialengine
Organizations
2 linked
SocialengineKarma(In)Security
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.