Junglewise Threat Intelligence

CVE-2026-49345: sourcentis Mercator SSRF in ConfigurationController

CVE-2026-49345 · Severity: info · CVSS 5.3 · Published 2026-06-19

Executive brief

Mercator is an open-source tool used for mapping and managing information systems. A security flaw in its configuration panel allows an authorized user to force the server to make unauthorized network requests to internal or external systems. This could allow an attacker to scan private internal networks or, in specific setups, take full control of the server by interacting with internal databases like Redis or Memcached.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the `testProvider()` method of the `ConfigurationController` located at `/admin/config/parameters`. The application passes user-supplied input directly to `curl_init()` without validating the URI scheme, hostname, or destination IP address. While the application appends `/api/dbInfo` to the input, attackers can bypass this by injecting a `#` fragment character to control the entire URL. An authenticated attacker with 'configure' permissions can use schemes like `telnet://` for internal port scanning or `gopher://` to interact with unauthenticated internal services like Redis or Memcached. Under specific conditions, such as reachable unauthenticated Redis instances or Memcached cache poisoning, this can lead to Remote Code Execution (RCE). The issue is patched in version 2025.05.19.

Affected products

  • sourcentis Mercator < 2025.05.19

Timeline

  • 2026-05-25: advisory: GitHub advisory published by developer
  • 2025-05-19: patched: Security fix released in version 2025.05.19
  • 2026-06-19: disclosed: NVD publication date

References

Related threats