Junglewise Threat Intelligence

CVE-2026-18856: Poesis Rhymix CMS server-side request forgery in data import

CVE-2026-18856 · Severity: medium · CVSS 4.7 · Published 2026-08-05

Executive brief

Rhymix CMS, a content management system, contains a vulnerability in its data import module that allows an authenticated administrator to make the server fetch arbitrary URLs, potentially exposing internal systems or cloud metadata. An attacker with admin credentials can input any URL into the import form, causing the server to request it on their behalf, bypassing network firewalls and exposing sensitive internal infrastructure.

Technical details

This is a server-side request forgery (SSRF) vulnerability in the procImporterAdminCheckXmlFile function of the importer.admin.controller.php file. The vulnerability occurs because user-controlled input from the 'filename' parameter is passed directly to PHP's fopen() function without URL validation, whitelist checks, or IP address restrictions. The attack requires administrator privileges (is_admin=Y) and network access to the admin panel. An attacker can supply malicious URLs to probe internal networks, scan ports, access cloud metadata endpoints, or retrieve sensitive configuration files. The vulnerability is fixed in version 2.1.34; users should upgrade immediately.

Affected products

  • Poesis Rhymix CMS up to 2.1.33

Timeline

  • 2026-08-05: disclosed: Vulnerability disclosed publicly
  • 2026: patched: Fixed in version 2.1.34

References