CVE-2026-39117
Deferred Deferred - Pending Action

Remote Code Execution in 66Uptime

Vulnerability report for CVE-2026-39117, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: MITRE

Description

An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
altumcode 66uptime to 54.0.0 (exc)
altumcode 66uptime_ping_servers_plugin to 2.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-39117 is a Server-Side Request Forgery (SSRF) vulnerability in AltumCode 66Uptime and its Ping Servers Plugin. It allows remote attackers to send arbitrary HTTP requests, ICMP pings, and TCP connections to any target via a publicly accessible endpoint. The vulnerability exists in versions before 54.0.0 for the main application and before 2.0.0 for the plugin.

Detection Guidance

Check if the AltumCode 66Uptime Ping Servers Plugin is installed and verify its version. Look for unusual outbound network traffic from the ping server endpoint, especially to internal or cloud metadata addresses like 169.254.169.254. Inspect logs for unexpected HTTP, ICMP, or TCP connections originating from the plugin.

Impact Analysis

This vulnerability can allow attackers to retrieve cloud instance metadata, including credentials, from services like AWS, Google Cloud, Microsoft Azure, and DigitalOcean. It may also enable unauthorized access to cloud resources, internal network scanning, API exposure, and denial-of-service attacks. If the ping server is hosted on-premises, it risks exposing internal corporate networks.

Mitigation Strategies

Upgrade to AltumCode 66Uptime v54.0.0 or later and the Ping Servers Plugin v2.0.0 or later. Enable API key authentication for both the main application and each ping server. Block outbound access to metadata endpoints and private IP ranges at the network level. Restrict inbound access to the ping server endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-39117. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart