Junglewise Threat Intelligence

CVE-2026-42141: Xibo CMS SSRF in Library Upload via URL

CVE-2026-42141 · Severity: high · CVSS 7.7 · Published 2026-05-12

Executive brief

Xibo CMS is a web-based management system for digital signage. A security flaw allows authorized users with library upload permissions to force the server to make unauthorized network requests. This could allow an attacker to scan internal company networks, access sensitive cloud configuration data, or interact with internal services that are not normally exposed to the internet.

Technical details

An authenticated Server-Side Request Forgery (SSRF) exists in the Xibo CMS Library upload via URL functionality. The vulnerability is caused by insufficient validation of user-supplied URLs, allowing an attacker with 'Library upload' privileges to initiate arbitrary HTTP requests from the server's context. This can be used to target internal infrastructure, access cloud metadata services like AWS IMDS, or bypass firewalls to interact with internal-only services. The issue is fixed in version 4.4.1; users unable to upgrade should restrict library upload permissions to trusted individuals.

Affected products

  • Xibo Signage Xibo CMS < 4.4.1

Timeline

  • 2026-03-24: patched: Fix available in release 4.4.1
  • 2026-04-07: disclosed: Responsible disclosure to vendor
  • 2026-04-23: advisory: Public disclosure of the vulnerability
  • 2026-05-12: other: CVE published to NVD

References