CVE-2026-9557
EUVD-2026-3327329.05.2026, 11:16
A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing requests to arbitrary internal or external destinations.
Awaiting analysis
This vulnerability is currently awaiting analysis.
Vulnerability Media Exposure