A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing requests to arbitrary internal or external destinations.
Metrics
Affected Vendors & Products
References
History
Fri, 29 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SSRF Vulnerability in Mautic Focus Component |
Fri, 29 May 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing requests to arbitrary internal or external destinations. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mautic
Published:
Updated: 2026-05-29T10:51:10.746Z
Reserved: 2026-05-26T08:36:47.057Z
Link: CVE-2026-9557
Updated: 2026-05-29T10:49:50.601Z
Status : Deferred
Published: 2026-05-29T11:16:17.853
Modified: 2026-05-29T15:39:34.620
Link: CVE-2026-9557
No data.
OpenCVE Enrichment
Updated: 2026-05-29T11:30:42Z