ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability
ZDI disclosed an unpatched SSRF information disclosure flaw (CVE-2026-92204, CVSS 7.7) in Airbyte's OneDrive connector, requiring authentication.
ZDI-26-704 describes a server-side request forgery vulnerability in the _get_shared_drive_object function of Airbyte's OneDrive connector. Remote authenticated attackers can initiate arbitrary server-side requests leading to information disclosure. The flaw scores CVSS 7.7, is tracked as CVE-2026-92204, and is published as a 0day advisory without a referenced fix.
- Unpatched SSRF flaw in Airbyte OneDrive connector
- Authenticated attackers can trigger arbitrary server-side requests
- Assigned CVE-2026-92204 with CVSS 7.7
- Disclosed via ZDI as a 0day advisory
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-92204 | NVD description · AI analysis pending | — | — | — | — | — |
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92204.
This source does not provide full text. Read it at zerodayinitiative.com.