Moderate severityNVD Advisory· Published Apr 15, 2026· Updated Jul 9, 2026
CVE-2026-40500
CVE-2026-40500
Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. The "Add Module from URL" feature requires superuser privileges (root-equivalent in ProcessWire) who already has unrestricted arbitrary code execution via standard module upload, making the SSRF vector incapable of providing incremental attack surface. The feature is also disabled by default and requires direct filesystem access to enable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
processwire/processwirePackagist | <= 3.0.255 | — |
Affected products
1Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.