Server-Side Request Forgery in Vvveb CMS Affects Admin Access
CVE-2026-55232

7.6HIGH

Key Information:

Vendor

Givanz

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-55232?

Vvveb CMS, a user-friendly content management system, had a vulnerability prior to version 1.0.8.6 that allowed server-side request forgery (SSRF). This vulnerability was caused by the CMS's failure to properly inspect IPv6 addresses, enabling an authenticated admin user to access internal services and cloud metadata by leveraging URLs with only AAAA records. The editor oEmbed proxy would fetch attacker-controlled URLs server-side, posing a risk of sensitive data exposure, including IAM credentials. This issue has been addressed in the updated version 1.0.8.6, ensuring enhanced security for users.

Affected Version(s)

Vvveb < 1.0.8.6

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.