CVE-2026-7065Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is the function uploadRemoteFile of the file packages/core/src/modules/upload/services/file-storage.service.ts of the component Remote Upload API. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-27); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-26: 1Mentions · 2026-04-27: 2Mentions · 2026-04-30: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-30: 104-2604-2704-30
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-261
General1
2026-04-272
Disclosure2
2026-04-301
Patch1
Full discourse4 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH Severity: CVE-2026-7065 (CVSS 7.3) BidingCC BuildingAI ≤26.0.1 vulnerable to SSRF via uploadRemoteFile function. Exploit public, vendor unresponsive. Patch immediately if using affected versions. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/yRibmVQlnD

    Post summary

    The tweet alerts about CVE-2026-7065, an SSRF flaw in BidingCC BuildingAI v≤26.0.1, noting a public exploit and urging users to apply the patch immediately.

    1000032
    11 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7065 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7065 #CVE-2026-7065 #CVE #High #CyberSecurity #InfoSec https://t.co/QQWyobDm1f

    Post summary

    The tweet announces CVE‑2026‑7065 with its severity rating and links to the NVD entry, but offers no additional details, fixes, or exploitation information.

    0000047
    141 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7065 Server-Side Request Forgery in BidingCC BuildingAI Remote Upload API Up to 26.0.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7065

    Post summary

    The text announces CVE-2026-7065, a Server‑Side Request Forgery vulnerability in BidingCC BuildingAI Remote Upload API up to version 26.0.1, without any PoC, exploit, patch, or active exploitation details.

    0000052
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-7065 A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is the function uploadRemoteFile of the file packages/core/src/modules/upload/services/file… https://www.cve.org/CVERecord?id=CVE-2026-7065

    Post summary

    CVE‑2026‑7065 is identified as affecting BidingCC BuildingAI's uploadRemoteFile function, but no exploit, patch, or advanced technical detail is provided.

    0000071
    57.3K followersView on X

Explore more