Back

MEDIUM

Unauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot Platform

Published Oct 2, 2026

Description

Missing Authorization vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner TR-CERT
Published Oct 2, 2026
Updated Oct 2, 2026
Reserved Aug 26, 2026

CISA Vulnrichment

Updated Oct 2, 2026

NVD

Status Deferred
Modified Oct 2, 2026

Red Hat

No data

ENISA EUVD

Assigner TR-CERT
Published Oct 2, 2026
Updated Oct 2, 2026

GitHub

No data