A vulnerability has been found in Kovah LinkAce up to 2.5.3 and classified as critical. This issue affects the function LinkRepository::update. The manipulation leads to server-side request forgery.

This vulnerability is traded as CVE-2026-35516. It is possible to initiate the attack remotely. There is no exploit available.

The affected component should be upgraded.