CVE-2026-9557 Details
Description
A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing requests to arbitrary internal or external destinations.
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Mautic Focus component, specifically in versions 4.0.0 and later. This vulnerability arises from inadequate validation of user-supplied URLs, allowing authenticated users to initiate outbound HTTP requests from the server. Exploitation of this vulnerability could facilitate internal network reconnaissance or direct requests to arbitrary internal or external destinations.
Users are advised to upgrade to Mautic versions 7.1.2, 6.0.9, 5.2.11, or 4.4.20. For those on the Extended Long-Term Support (ELTS) plan, version 4.4.20 is recommended. If an immediate upgrade is not possible, consider disabling or limiting external network access from the Mautic web server to internal-only subnets or local hosts.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 29, 2026CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/mautic/mautic/security/advisories/GHSA-jmv8-8j9j-rcpc | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mautic | >= 4.0.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | New CVE Received | [email protected] |
Volerion