CVE-2026-3588: Ikea Dirigera Firmware

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private keys by sending a crafted request.

Affected products

  • Ikea Dirigera Firmware: version 2.866.4 only

Published 2026-03-09. Last modified 2026-06-17.