Medium severity6.4NVD Advisory· Published May 29, 2026· Updated Jul 21, 2026
CVE-2026-9557
CVE-2026-9557
Description
A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing requests to arbitrary internal or external destinations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mautic/corePackagist | >= 4.0.0, <= 4.4.13 | — |
mautic/corePackagist | >= 5.0.0, < 5.2.11 | 5.2.11 |
mautic/corePackagist | >= 6.0.0, < 6.0.9 | 6.0.9 |
mautic/corePackagist | >= 7.0.0, < 7.1.2 | 7.1.2 |
Affected products
3Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.