CVE-2026-31955 Details
Description
Xibo is an open source digital signage platform with a web content management system and Windows display player software. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions prior to 4.4.1 allows users with DataSet permissions to make arbitrary HTTP requests from the CMS server to internal or external network resources. This can be exploited to scan internal infrastructure, access local cloud metadata endpoints (e.g., AWS IMDS), interact with internal services that lack authentication, or exfiltrate data. Exploitation of the vulnerability is possible on behalf of an authorized user who has both of the following privileges, which are not granted to non-admins as standard: Include "Add DataSet" button to allow for additional DataSets to be created independently to Layouts. Users should upgrade to version 4.4.1 which fixes this issue. Upgrading to a fixed version is necessary to remediate. Users unable to upgrade should revoke such privileges from users they do not trust.
A server-side request forgery (SSRF) vulnerability has been identified in Xibo CMS versions prior to 4.4.1. This vulnerability allows authenticated users with DataSet permissions to make arbitrary HTTP requests from the CMS server to internal or external network resources. Exploitation could lead to scanning internal infrastructure, accessing local cloud metadata endpoints (such as AWS IMDS), interacting with unauthenticated internal services, or exfiltrating data. The vulnerability requires an authorized user to have specific privileges that are not typically granted to non-admins.
Users should upgrade to Xibo CMS version 4.4.1, which addresses this vulnerability. For those unable to upgrade, it is recommended to revoke DataSet permissions from untrusted users.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xibosignage/xibo-cms/releases/tag/4.4.1 | [email protected] | Release Notes |
| https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-5q58-9vhx-xg2p | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| xibosignage xibo | < 4.4.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Apr 24, 2026 | New CVE Received | [email protected] |