Arbitrary URL Vulnerability in Squidex Content Management System
CVE-2026-41170

7.2HIGH

Key Information:

Vendor

Squidex

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-41170?

The Squidex content management system, prior to version 7.23.0, contains a vulnerability in the RestoreController.PostRestoreJob endpoint that allows administrators to submit arbitrary URLs for downloading backup archives. This functionality is executed using the 'Backup' HttpClient without appropriate server-side request forgery (SSRF) protections in place. A malicious or compromised administrator can exploit this flaw to gain access to internal network services and cloud metadata endpoints, potentially leading to significant exposure of sensitive internal resources. Version 7.23.0 addresses this vulnerability by imposing necessary security measures.

Affected Version(s)

squidex < 7.23.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.