CVE-2026-3588

A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private keys by sending a crafted request.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ikea:dirigera_firmware:2.866.4:*:*:*:*:*:*:*
cpe:2.3:h:ikea:dirigera:-:*:*:*:*:*:*:*

History

06 May 2026, 14:22

Type Values Removed Values Added
First Time Ikea dirigera Firmware
Ikea
Ikea dirigera
References () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-3588 - () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-3588 - Third Party Advisory
CPE cpe:2.3:o:ikea:dirigera_firmware:2.866.4:*:*:*:*:*:*:*
cpe:2.3:h:ikea:dirigera:-:*:*:*:*:*:*:*

11 Mar 2026, 13:53

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de falsificación de petición del lado del servidor (SSRF) en IKEA Dirigera v2.866.4 permite a un atacante exfiltrar claves privadas enviando una petición manipulada.

09 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 16:16

Updated : 2026-05-06 14:22


NVD link : CVE-2026-3588

Mitre link : CVE-2026-3588

CVE.ORG link : CVE-2026-3588


JSON object : View

Products Affected

ikea

  • dirigera_firmware
  • dirigera
CWE
CWE-918

Server-Side Request Forgery (SSRF)