Junglewise Threat Intelligence

CVE-2026-5618: Kalcaddle kodbox SSRF in shareMake/shareCheck

CVE-2026-5618 · Severity: medium · CVSS 5.6 · Published 2026-04-06

Technologies: Kalcaddle Kodbox. Vendors: Kalcaddle.

Executive brief

Kalcaddle kodbox, a web-based document management and collaboration platform, contains a security flaw in its file-sharing components. An attacker can exploit this to force the server to make unauthorized requests to internal or external systems. This could lead to the exposure of internal network information or unauthorized access to private services.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Kalcaddle kodbox up to version 1.64 within the shareMake/shareCheck component. The flaw is triggered by manipulating the 'siteFrom' or 'siteTo' arguments, allowing a remote attacker to induce the server to perform unintended requests. While the attack can be carried out over the network without authentication, it is characterized by high complexity and difficult exploitability. A public exploit is currently available. As of the advisory date, the vendor has not responded to disclosure attempts, and no official patch has been confirmed.

Affected products

  • kalcaddle kodbox up to 1.64

Timeline

  • 2026-04-06: disclosed: Public disclosure of the vulnerability and exploit.
  • 2026-04-06: advisory: CVE-2026-5618 published.

References

Related threats