Vulnerability  ·  2026-10-03

HAVELSAN Sef AI Chatbot Platform (EOL): SQL injection, SSRF, missing authz, and TLS validation flaws (CVE-2026-80298/80443/80337/80464)

VulnerabilityMedium impactGlobalCVE-2026-80298
NVD published a four-CVE cluster on 2026-10-02 for the HAVELSAN Sef AI Chatbot Platform (before 2.1): SQL injection (CVE-2026-80298, CVSS 8.8), certificate-validation AiTM weakness (CVE-2026-80443), missing authorization (CVE-2026-80337), and SSRF (CVE-2026-80464). The vendor states the product is not supported.
An EOL AI chatbot product with SQLi/SSRF/authz gaps is a live-risk flag for any org still running it; unsupported status means patching is impossible, so the action is decommission — Tier C due to narrow/niche blast radius but worth surfacing.
SQL injection into the chatbot backend; certificate-validation gaps enabling AiTM interception of chatbot traffic; missing ACL checks; and SSRF from the platform. All four published as a cluster by the Turkish national CERT (TR-26-1241) on 2026-10-02.
HAVELSAN Sef - AI Chatbot Platform < 2.1 (EOL / unsupported)
No fix available — product is end-of-life/unsupported; remediate by retiring the platform and not exposing it to untrusted networks.
NVD CVE-2026-80298Turkish National CERT advisory TR-26-1241
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →