CVE-2026-39117 Details
Description
An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php
A Server-Side Request Forgery (SSRF) vulnerability exists in AltumCode 66Uptime versions prior to 54.0.0 and in the 66Uptime ping-servers plugin versions prior to 2.0.0. This vulnerability allows remote attackers to execute arbitrary code by sending requests to the ping server endpoint without authentication. Exploitation can lead to unauthorized access to cloud instance metadata, internal networks, and external targets, with potential for significant damage depending on the accessed resources.
Users should update to AltumCode 66Uptime version 54.0.0 or later and ping-servers plugin version 2.0.0 or later. After upgrading, it is crucial to configure a strong, unique API key for each ping server, as the API key is optional and defaults to empty. Implementing network-level controls to block access to cloud metadata endpoints and internal IP ranges is also recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.glimmernet.com/security/gt-2026-001-ssrf-66uptime-ping-servers/ | CISA-ADP | AdvisoryExploitRemedy |
| https://www.glimmernet.com/security/gt-2026-001-ssrf-66uptime-ping-servers/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| AltumCode 66Uptime | < 54.0.0 (semver) |
CPE
Remediation
| |
| AltumCode 66Uptime ping-servers | < 2.0.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion