OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-55232

HIGH · CVSS 7.6 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Vvveb CMS versions prior to 1.0.8.6 are vulnerable to a Server-Side Request Forgery (SSRF) flaw that allows authenticated admin users to access internal services and cloud metadata by exploiting IPv6 addresses or domains with only AAAA records. This vulnerability can lead to the exposure of sensitive information, including IAM credentials, posing a significant risk to organizations using this CMS. Administrators of affected Vvveb installations should prioritize upgrading to the patched version to mitigate potential security breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55232
Severity
HIGH
CVSS
7.6
EPSS
0.32%

Original NVD Description

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and never inspects IPv6, so any host that lacks an A record passes a private-range check. Editor oEmbed proxy fetches an attacker-supplied URL server side and reflects a response body, so an authenticated admin-panel user (default role site_admin or higher) can read internal-only services and cloud metadata, including IAM credentials, using an IPv6 literal or a domain that carries only an AAAA record. This issue has been patched in version 1.0.8.6.