CVE-2026-85662: Marqo-Ai Marqo

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Marqo 2.26.0 contains a server-side request forgery vulnerability in the add_documents endpoint that allows unauthenticated attackers to trigger requests to arbitrary URLs by supplying malicious media field values. Attackers can exploit download_image_from_url and fetch_content_sample functions which lack destination filtering and host validation to access internal services and cloud metadata endpoints.

Affected products

  • Marqo-Ai Marqo: up to and including 2.26.0

Published 2026-09-04. Last modified 2026-09-23.