CVE-2026-77112 PUBLISHED

SSRF Leading to JWT Token Disclosure in Global IT Informatics' Weoll

Assigner: TR-CERT
Reserved: 20.08.2026 Published: 23.09.2026 Updated: 23.09.2026

Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server Side Request Forgery.

This issue affects Weoll: before 3.2.45.44.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor Global IT Informatics Technology Services Inc.
Product Weoll
Versions Default: unaffected
  • affected from 0 to 3.2.45.44 (excl.)

Credits

  • Hamza Metin Gerdan finder

References

Problem Types

  • CWE-918 Server-Side request forgery (SSRF) CWE

Impacts

  • CAPEC-664 Server Side Request Forgery