Junglewise Threat Intelligence

CVE-2026-19733: Yordam Library Information and Document Automation Program server-side request forgery

CVE-2026-19733 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: Yordam Library Information and Document Automation Program.

Executive brief

Yordam's Library Information and Document Automation Program is a document management system used by organizations to organize and automate their information workflows. A server-side request forgery (SSRF) vulnerability allows attackers to make unauthorized requests to internal systems and resources, potentially exposing sensitive internal data, accessing restricted services, or compromising connected infrastructure.

Technical details

A server-side request forgery (SSRF) vulnerability exists in Yordam's Library Information and Document Automation Program versions before 22.2. The vulnerability allows an attacker to craft requests that cause the vulnerable application to make arbitrary HTTP requests to internal or external resources on behalf of the application server. This could enable access to internal APIs, metadata services, or other backend systems not directly accessible from the network. The exact attack vector and preconditions are not detailed in the available references, but SSRF vulnerabilities typically require network access to the affected service. Patches are available in version 22.2 and later.

Affected products

  • Yordam Library Information and Document Automation Program before 22.2

Timeline

  • 2026-09-09: disclosed: Published on NVD and Turkish CIMCI advisory

References