Server-Side Request Forgery Vulnerability in Aimeos Pagible Content Management System
CVE-2026-49262

3LOW

Key Information:

Vendor

Aimeos

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-49262?

Prior to version 0.10.4, the Aimeos Pagible content management system is susceptible to a Server-Side Request Forgery (SSRF) due to a flaw in the administrative proxy route (cmsproxy). This vulnerability arises from a Time-of-Check to Time-of-Use (TOCTOU) race condition between the URL validation process and the ensuing HTTP request. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive internal network resources and cloud metadata endpoints, posing significant security risks.

Affected Version(s)

pagible < 0.10.4

References

CVSS V3.1

Score:
3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.