6.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Description
A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing requests to arbitrary internal or external destinations.
Basic Information
ID
CVE-2026-9557
Source
Mautic
Published
May 29, 2026 at 09:38
Modified
May 29, 2026 at 10:51
Affected Product
Version
7.0.0
Affected Versions
4.0.0
5.0.0
6.0.0
7.0.0
5.0.0
6.0.0
7.0.0