Junglewise Threat Intelligence

CVE-2026-72598: Apioo Fusio server-side request forgery via webhook registration

CVE-2026-72598 · Severity: medium · CVSS 6.5 · Published 2026-08-11

Executive brief

Apioo Fusio is an API management platform that allows developers to build and deploy APIs. Authenticated users with consumer-level permissions can register webhooks with URLs pointing to internal network addresses, causing the server to make HTTP requests to systems that should be unreachable from outside. An attacker could exploit this to scan internal networks, interact with internal services, or trigger actions on systems behind the firewall.

Technical details

This is a server-side request forgery (SSRF) vulnerability in the webhook registration endpoint of Apioo Fusio 8.8.3. The endpoint validates webhook URLs using FILTER_VALIDATE_URL but does not implement IP address or hostname filtering, allowing registration of URLs pointing to internal network ranges (e.g., 127.0.0.1, 192.168.x.x, 10.x.x.x). When the corresponding event fires, the server issues an HTTP POST request to the attacker-supplied internal URL. The vulnerability requires authentication as a consumer-role user but no additional preconditions. An attacker can use this to perform internal network reconnaissance, interact with internal services, or launch attacks against services accessible only from within the network perimeter.

Affected products

  • Apioo Fusio 8.8.3

Timeline

  • 2026-08-11: disclosed

References

Related threats