CVE-2026-9557

MEDIUM

Mautic Focus - Authenticated Server-Side Request Forgery via URL Parameter

Title source: llm
STIX 2.1

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing requests to arbitrary internal or external destinations.

Scores

CVSS v3 6.4
EPSS 0.0015
EPSS Percentile 4.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (4)
mautic/core 4.0.0 - 4.4.13Packagist
mautic/core 5.0.0 - 5.2.11Packagist
mautic/core 6.0.0 - 6.0.9Packagist
mautic/core 7.0.0 - 7.1.2Packagist
Published May 29, 2026
Tracked Since May 29, 2026