Server-Side Request Forgery in Vvveb CMS Affects Admin Access
CVE-2026-55232
7.6HIGH
What is CVE-2026-55232?
Vvveb CMS, a user-friendly content management system, had a vulnerability prior to version 1.0.8.6 that allowed server-side request forgery (SSRF). This vulnerability was caused by the CMS's failure to properly inspect IPv6 addresses, enabling an authenticated admin user to access internal services and cloud metadata by leveraging URLs with only AAAA records. The editor oEmbed proxy would fetch attacker-controlled URLs server-side, posing a risk of sensitive data exposure, including IAM credentials. This issue has been addressed in the updated version 1.0.8.6, ensuring enhanced security for users.
Affected Version(s)
Vvveb < 1.0.8.6
