No advisories yet.
Solution
No solution given by the vendor.
Workaround
There are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets and local hosts is recommended.
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mautic
Mautic mautic |
|
| Vendors & Products |
Mautic
Mautic mautic |
Fri, 29 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SSRF Vulnerability in Mautic Focus Component |
Fri, 29 May 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing requests to arbitrary internal or external destinations. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Mautic
Published:
Updated: 2026-05-29T10:51:10.746Z
Reserved: 2026-05-26T08:36:47.057Z
Link: CVE-2026-9557
Updated: 2026-05-29T10:49:50.601Z
Status : Deferred
Published: 2026-05-29T11:16:17.853
Modified: 2026-05-29T15:39:34.620
Link: CVE-2026-9557
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:47:11Z