Junglewise Threat Intelligence

CVE-2026-48707: InstantCMS SSRF in file upload via redirect bypass

CVE-2026-48707 · Severity: low · CVSS 3.1 · Published 2026-09-08

Executive brief

InstantCMS is a free content management system used to build websites. The file upload feature includes an option to upload files from a remote URL, but a vulnerability allows authenticated users to bypass security checks by using HTTP redirects to reach internal network services. An attacker could scan or access internal networks, databases, or cloud metadata services that should not be publicly reachable.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in system/core/uploader.php (lines 509-532) where the "upload from URL" feature validates the initial URL against a private IP address blacklist but fails to re-validate the destination URL after following HTTP redirects. When the server parses the Location header and recursively calls uploadFromLink(), the redirect target bypasses the FILTER_FLAG_NO_PRIV_RANGE and FILTER_FLAG_NO_RES_RANGE checks. The vulnerability requires authentication and network access to the upload endpoint. An attacker can exploit this to enumerate internal network services, access internal APIs, admin panels, or cloud metadata endpoints (e.g., 169.254.169.254). Version 2.18.2 contains a fix that re-validates redirect targets and enforces maximum redirect limits.

Affected products

  • instantsoft InstantCMS prior to 2.18.2

Timeline

  • 2026-09-08: disclosed
  • 2026-05-22: patched: Version 2.18.2

References