Server-Side Request Forgery Vulnerability in InstantCMS by InstantSoft
CVE-2026-48707

3.1LOW

Key Information:

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-48707?

InstantCMS, an open-source content management system, has a vulnerability in its file upload feature that can be exploited to launch Server-Side Request Forgery (SSRF) attacks. Specifically, when users upload files via the 'upload from URL' option, if the process encounters an HTTP redirect, it may inadvertently bypass the blacklist checks for private IP addresses. This flaw allows authenticated users to potentially access and scan internal network services, posing a significant security risk. The issue was addressed in version 2.18.2, making it essential for users to update to this release to ensure their systems are secure.

Affected Version(s)

icms2 < 2.18.2

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.