CVE-2026-33486 Details
Description
Roadiz is a polymorphic content management system based on a node system that can handle many types of services. A vulnerability in roadiz/documents prior to versions 2.7.9, 2.6.28, 2.5.44, and 2.3.42 allows an authenticated attacker to read any file on the server's local file system that the web server process has access to, including highly sensitive environment variables, database credentials, and internal configuration files. Versions 2.7.9, 2.6.28, 2.5.44, and 2.3.42 contain a patch.
A server-side request forgery (SSRF) vulnerability has been identified in Roadiz Documents versions prior to 2.7.9, 2.6.28, 2.5.44, and 2.3.42. This vulnerability allows authenticated attackers with the 'ROLE_ACCESS_DOCUMENTS' permission to read any file on the server's local file system that the web server process can access. Exploitation of this vulnerability could lead to the disclosure of sensitive information such as environment variables, database credentials, and internal configuration files.
Users can upgrade to Roadiz Documents versions 2.7.9, 2.6.28, 2.5.44, or 2.3.42 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| roadiz core-bundle-dev-app | < 2.3.42 >= 2.4.0, < 2.5.44 >= 2.6.0, < 2.6.28 >= 2.7.0, < 2.7.9 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | New CVE Received | [email protected] |