Skip to main content
Vulnerability Database/CVE-2026-86173

CVE-2026-86173: MindsDB Web Crawler SSRF Vulnerability

CVE-2026-86173 is an SSRF flaw in MindsDB web crawler that lets unauthenticated attackers access internal services and cloud metadata by exploiting default configurations. This article covers technical details, versions affected, and mitigation.

Published:

CVE-2026-86173 Overview

CVE-2026-86173 is a server-side request forgery (SSRF) vulnerability in MindsDB through version 26.1.0. The flaw resides in the web crawler handler and allows unauthenticated attackers to force the server to fetch arbitrary URLs. Attackers submit caller-controlled URLs to CrawlerTable.list, which the handler retrieves without validating the destination. The default configuration ships with an empty allowlist, which bypasses the intended URL restriction control. Successful exploitation grants access to internal services and cloud metadata endpoints, exposing credentials and infrastructure data. The vulnerability is tracked under CWE-918: Server-Side Request Forgery.

Critical Impact

Unauthenticated attackers can reach internal-only services and cloud instance metadata endpoints, enabling credential theft and lateral movement inside the target environment.

Affected Products

  • MindsDB versions up to and including 26.1.0
  • MindsDB web_handler integration component
  • Deployments relying on the default empty allowlist configuration

Discovery Timeline

  • 2026-09-05 - CVE-2026-86173 published to the National Vulnerability Database
  • 2026-09-08 - Last updated in NVD database

Technical Details for CVE-2026-86173

Vulnerability Analysis

MindsDB exposes a web crawler integration that fetches remote content on behalf of the caller. The CrawlerTable.list method in mindsdb/integrations/handlers/web_handler/web_handler.py accepts URLs supplied through query parameters and issues outbound HTTP requests. The handler is reachable without authentication in the default deployment. An allowlist mechanism exists in mindsdb/utilities/config.py, but it defaults to an empty list. An empty allowlist is interpreted as permissive rather than restrictive, so all destinations are accepted. This makes any MindsDB instance reachable over the network usable as an outbound HTTP proxy.

Root Cause

The root cause is missing validation of user-controlled URLs combined with an insecure default configuration [CWE-918]. The allowlist check treats the empty state as "allow all" rather than "deny all". Operators who deploy MindsDB without customizing configuration inherit the permissive behavior. The handler also lacks IP-based filtering for private ranges, loopback addresses, and link-local metadata endpoints such as 169.254.169.254.

Attack Vector

Exploitation requires only network access to the MindsDB HTTP API. An unauthenticated attacker sends a request that invokes the web crawler with a URL pointing at an internal target. The MindsDB server retrieves the target and returns the response body to the attacker. Typical targets include cloud instance metadata services on AWS, Azure, and GCP, internal admin dashboards, and unauthenticated services bound to loopback interfaces. See the VulnCheck Advisory for MindsDB and the vulnerable code path in the MindsDB Web Handler Code for technical detail.

Detection Methods for CVE-2026-86173

Indicators of Compromise

  • Outbound HTTP requests originating from the MindsDB process to internal RFC1918 addresses, loopback, or 169.254.169.254
  • Access log entries invoking the web_handler integration or CrawlerTable.list from unauthenticated sessions
  • Unexpected cloud IAM token retrievals traced to the MindsDB host
  • Spikes in outbound requests to attacker-controlled domains sourced from the MindsDB service account

Detection Strategies

  • Inspect application logs for CrawlerTable.list invocations and correlate the URL parameter against an allowlist of legitimate destinations
  • Deploy egress filtering rules that alert when the MindsDB host contacts cloud metadata endpoints or private ranges
  • Baseline normal crawler destinations and flag anomalous host or scheme values including file://, gopher://, and http://127.0.0.1

Monitoring Recommendations

  • Forward MindsDB HTTP access logs and process network telemetry to a centralized analytics platform for correlation
  • Monitor cloud audit logs for use of instance metadata credentials from unexpected source workloads
  • Alert on new or modified entries in the MindsDB config.py allowlist configuration

How to Mitigate CVE-2026-86173

Immediate Actions Required

  • Restrict network access to the MindsDB HTTP API using firewall rules or a reverse proxy that enforces authentication
  • Configure an explicit allowlist of permitted crawler destinations in the MindsDB configuration file
  • Enforce Instance Metadata Service Version 2 (IMDSv2) on AWS and equivalent hardened metadata configurations on Azure and GCP
  • Block egress from the MindsDB host to 169.254.169.254 and private ranges that the service does not require

Patch Information

No fixed version is identified in the enriched CVE data at the time of publication. Track the MindsDB Issue Tracker and the VulnCheck Advisory for MindsDB for upstream fix availability and apply the patched release as soon as it is published.

Workarounds

  • Disable the web_handler integration if crawling functionality is not required for the deployment
  • Place MindsDB behind an authenticating reverse proxy and reject anonymous requests to crawler endpoints
  • Run MindsDB in a network segment with strict egress controls that deny access to metadata services and internal admin interfaces
bash
# Example egress restriction using iptables on the MindsDB host
iptables -A OUTPUT -d 169.254.169.254 -j DROP
iptables -A OUTPUT -d 10.0.0.0/8 -p tcp --dport 80 -j DROP
iptables -A OUTPUT -d 127.0.0.0/8 ! -o lo -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.