THREAT OPS › Threat News › [NVD] CVE-2026-86273 (HIGH 7.3) — A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the component HTML-to-PDF Endpoint. This manipulation of the argument
[NVD] CVE-2026-86273 (HIGH 7.3) — A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the component HTML-to-PDF Endpoint. This manipulation of the argument
CVE-2026-86273 CVSS: 7.3 HIGH Published: 2026-09-07T06:17:23.580
A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the component HTML-to-PDF Endpoint. This manipulation of the argument html causes server-side request forgery. The attack m
Indicators of compromise
- CVE-2026-86273cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86273