CVE-2026-9557 PUBLISHED

Assigner: Mautic
Reserved: 26.05.2026 Published: 29.05.2026 Updated: 29.05.2026

A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing requests to arbitrary internal or external destinations.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CVSS Score: 6.4

Product Status

Package Collection https://packagist.org
Package Name mautic/core
Versions Default: unaffected
  • affected from 4.0.0 to 4.4.20 (excl.)
  • affected from 5.0.0 to 5.2.11 (excl.)
  • affected from 6.0.0 to 6.0.9 (excl.)
  • affected from 7.0.0 to 7.1.2 (excl.)

Workarounds

There are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets and local hosts is recommended.

Credits

  • Mateus (@r1beirin) finder
  • Nguyen Huy Vu Dung (@dungNHVhust) finder
  • Patryk Gruszka (@patrykgruszka) remediation developer
  • John Linhart (@escopecz) remediation reviewer
  • Leuchtfeuer Digital Marketing (@Leuchtfeuer) sponsor

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE

Impacts

  • CAPEC-664 Server Side Request Forgery