Junglewise Threat Intelligence

CVE-2026-86273: Projeto SIGA server-side request forgery in HTML-to-PDF endpoint

CVE-2026-86273 · Severity: high · CVSS 7.3 · Published 2026-09-07

Executive brief

Projeto SIGA is a Brazilian government document management system used for managing official communications and workflows. An unauthenticated attacker can exploit a flaw in the HTML-to-PDF conversion feature to make the SIGA server fetch arbitrary URLs, potentially exposing internal services, accessing private resources, or conducting network reconnaissance against systems only reachable from the server.

Technical details

The vulnerability is a server-side request forgery (SSRF) in the HTML-to-PDF endpoint at POST /sigaex/public/app/util/html-pdf, implemented in the ExUtilController.getUrl() method. The endpoint accepts unauthenticated requests and passes user-controlled HTML parameters to a Flying Saucer renderer, which fetches embedded resource URLs (such as image sources) without destination allowlisting or validation. The underlying SigaHTTP.fetch() function lacks timeout and access restrictions, allowing attackers to reach loopback addresses, private networks, and link-local ranges. The vulnerability affects versions 5.4.10 through 11.1.1; no patch is currently available.

Affected products

  • Projeto SIGA SIGA 5.4.10 through 11.1.1

Timeline

  • 2026-07-25: disclosed: Issue opened on GitHub
  • 2026-09-07: advisory: CVE-2026-86273 published
  • 2026-09-07: other: Public exploit code available

References

Related threats