CVE-2026-55232
Deferred Deferred - Pending Action

Server-Side Request Forgery in Vvveb CMS

Vulnerability report for CVE-2026-55232, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and never inspects IPv6, so any host that lacks an A record passes a private-range check. Editor oEmbed proxy fetches an attacker-supplied URL server side and reflects a response body, so an authenticated admin-panel user (default role site_admin or higher) can read internal-only services and cloud metadata, including IAM credentials, using an IPv6 literal or a domain that carries only an AAAA record. This issue has been patched in version 1.0.8.6.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vvveb vvveb to 1.0.8.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a server-side request forgery (SSRF) vulnerability in Vvveb CMS versions before 1.0.8.6. The issue occurs because the URL validation function only checks IPv4 addresses, allowing IPv6 literals or domains with only AAAA records to bypass private-range checks. An authenticated admin can exploit this to read internal services, cloud metadata, and sensitive credentials by sending crafted requests to the oEmbed proxy endpoint.

Detection Guidance

Check if your Vvveb installation is running version 1.0.8.5 or earlier. Inspect the system/functions.php file for the validateUrl() function and verify if it only uses gethostbynamel() without IPv6 support. Test for SSRF by sending crafted requests to the oEmbedProxy endpoint with IPv6 literals or domains lacking A records.

Impact Analysis

An attacker with admin access could read internal-only services, cloud metadata, and sensitive credentials like IAM keys. This could lead to unauthorized access to internal resources, potential privilege escalation, and exposure of sensitive data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Non-compliance may result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Upgrade Vvveb to version 1.0.8.6 or later immediately. Review and restrict access to the admin panel, especially for site_admin roles. Implement network-level controls to block outbound requests to internal IP ranges. Monitor logs for unusual oEmbedProxy requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55232. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart