CVE-2026-35548

8.5

Guardsix · ODBC Enrichment Plugins

A logic flaw in Guardsix ODBC Enrichment Plugins allows authenticated operators to perform SSRF and misuse stored credentials by retaining them when modifying connection endpoints.

Executive summary

An authenticated logic flaw in Guardsix ODBC Enrichment Plugins allows attackers to redirect database connections and misuse stored credentials, posing a significant risk of internal system compromise.

Vulnerability

The vulnerability is a logic flaw where stored database credentials are not cleared when an administrator updates the target Host, IP address, or Port of an Enrichment Source. An authenticated operator user can exploit this to redirect connection traffic to unintended internal systems, facilitating Server Side Request Forgery (SSRF) and the unauthorized use of cached credentials.

Business impact

This vulnerability carries a CVSS score of 8.5, indicating a high severity risk. Successful exploitation allows an attacker to pivot from the application to internal network resources, potentially leading to unauthorized data access or further lateral movement within the environment. The impact is elevated by the potential for credential misuse, which could compromise the integrity and confidentiality of sensitive database information.

Remediation

Immediate Action: Update the Guardsix ODBC Enrichment Plugins to version 5.2.1 or later to ensure the credential cache is correctly invalidated upon endpoint modification.

Proactive Monitoring: Review access logs for the Enrichment Source configuration module and monitor for unusual database connection requests originating from the plugin service.

Compensating Controls: Restrict administrative access to the Enrichment Source configuration interface to only essential personnel and implement strict egress filtering on the server hosting the plugins to limit potential SSRF impact.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for unauthorized access to internal systems, immediate remediation is required. Organizations should prioritize updating to version 5.2.1 to eliminate the credential reuse flaw. Until the update is applied, ensure that access to the configuration console is strictly audited and limited to trusted administrators.

Sources