VORANT. Threat Intelligence Sign in Get the full feed

GREENmod named pipe flaw enables SSRF

medium vulnerability

A misconfigured named pipe ACL in GREENmod lets attackers upload files processed with service privileges, enabling SSRF via SMB/WebDAV; fixed in 2.8.33.

CERT Polska coordinated disclosure of a vulnerability in GREENmod, software that uses named pipes for inter-process communication between plugins, its web portal, and a system service. Incorrectly configured access control lists on these pipes allow an unauthenticated or low-privileged attacker to write directly to the pipe stream and submit arbitrary XML or JSON content, which is then processed with the privileges of the account running the service.

Exploitation of this flaw enables Server-Side Request Forgery against any Windows host running the GREENmod agent that supports SMB or WebDAV communication, potentially allowing an attacker to coerce the affected service into making requests or connections to internal or attacker-controlled resources. The vendor has resolved the issue in version 2.8.33, and organizations running GREENmod should upgrade promptly. The report credits researcher Marcin Ressel for responsibly disclosing the flaw through CERT Polska's coordinated vulnerability disclosure process.

Mentioned in this report

Vulnerabilities CVE-2026-5131

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-5131

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free