ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 2 sources: “ZDI discloses two 0day SSRF information disclosure vulnerabilities (CVE-2026-92203, CVE-2026-92204) in Airbyte SharePoint and OneDrive connectors” — merged summary and timeline →

ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability

mediumVulnerabilityimportance 38CVE-2026-92204
AI summary · glm-5.3-flash

ZDI disclosed an unpatched SSRF information disclosure flaw (CVE-2026-92204, CVSS 7.7) in Airbyte's OneDrive connector, requiring authentication.

ZDI-26-704 describes a server-side request forgery vulnerability in the _get_shared_drive_object function of Airbyte's OneDrive connector. Remote authenticated attackers can initiate arbitrary server-side requests leading to information disclosure. The flaw scores CVSS 7.7, is tracked as CVE-2026-92204, and is published as a 0day advisory without a referenced fix.

  • Unpatched SSRF flaw in Airbyte OneDrive connector
  • Authenticated attackers can trigger arbitrary server-side requests
  • Assigned CVE-2026-92204 with CVSS 7.7
  • Disclosed via ZDI as a 0day advisory

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-92204

NVD description · AI analysis pending
Full article

This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92204.

This source does not provide full text. Read it at zerodayinitiative.com.