ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 2 sources: “ZDI discloses two 0day SSRF information disclosure vulnerabilities (CVE-2026-92203, CVE-2026-92204) in Airbyte SharePoint and OneDrive connectors” — merged summary and timeline →

ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability

mediumVulnerabilityimportance 38CVE-2026-92203
AI summary · glm-5.3-flash

ZDI disclosed an unpatched SSRF information disclosure flaw (CVE-2026-92203, CVSS 7.7) in Airbyte's SharePoint connector, exploitable by authenticated remote users.

The Zero Day Initiative published ZDI-26-703 describing a server-side request forgery vulnerability in the _get_shared_drive_object function of Airbyte's SharePoint connector. Remote attackers can initiate arbitrary server-side requests to disclose information, though valid authentication credentials are required. The flaw carries a CVSS score of 7.7 and is tracked as CVE-2026-92203; it is flagged as a 0day with no vendor patch referenced.

  • Unpatched SSRF flaw in Airbyte SharePoint connector
  • Authenticated attackers can trigger arbitrary server-side requests
  • Assigned CVE-2026-92203 with CVSS 7.7
  • Disclosed via ZDI as a 0day advisory

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-92203

NVD description · AI analysis pending
Full article

This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92203.

This source does not provide full text. Read it at zerodayinitiative.com.