Junglewise Threat Intelligence

CVE-2026-57947: Pinpoint SSRF in webhook registration endpoint

CVE-2026-57947 · Severity: high · CVSS 8.5 · Published 2026-06-29

Executive brief

Pinpoint, an application performance management tool, contains a security flaw in its webhook registration system. An authorized user can provide internal web addresses that the server will then contact when an alarm is triggered. This allows an attacker to bypass network security controls to access sensitive internal data or interact with private cloud services that are not normally accessible from the internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Pinpoint versions up to and including 3.1.0. The vulnerability is located in the webhook registration endpoint, which fails to validate or sanitize user-provided URLs against internal network ranges. An authenticated attacker can register a webhook pointing to internal hosts or cloud metadata services (e.g., 169.254.169.254). By subsequently triggering an alarm threshold breach, the attacker can force the Pinpoint server to send POST requests to these internal targets. This can lead to unauthorized access to internal resources, sensitive data exposure, or further exploitation of internal services. The issue is addressed in version 3.1.1.

Affected products

  • pinpoint-apm Pinpoint through 3.1.0

Timeline

  • 2026-06-29: advisory: Advisory published by VulnCheck and NVD
  • 2026-06-29: disclosed

References