Junglewise Threat Intelligence

CVE-2026-9557: Mautic Focus component Server-Side Request Forgery

CVE-2026-9557 · Severity: medium · CVSS 6.4 · Published 2026-05-29

Technologies: Mautic. Vendors: Mautic.

Executive brief

Mautic, an open-source marketing automation platform, contains a vulnerability in its Focus component. An authorized user could exploit this flaw to force the server to make unauthorized requests to internal or external systems. This could allow an attacker to map out private internal network infrastructure or bypass firewalls to access sensitive internal services.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the MauticFocusBundle due to insufficient validation of user-supplied URLs. An authenticated attacker with access to the Mautic panel can provide a malicious URL that the server will then attempt to fetch. This can be used for internal port probing, network reconnaissance, or accessing internal services that are not exposed to the public internet. The vulnerability is tracked as CVE-2026-9557 and has been patched in versions 4.4.20 (ELTS), 5.2.11, 6.0.9, and 7.1.2.

Affected products

  • Mautic Mautic >= 4.0.0, <= 4.4.13; >= 5.0.0, < 5.2.11; >= 6.0.0, < 6.0.9; >= 7.0.0, < 7.1.2

Timeline

  • 2026-05-29: disclosed: NVD publication date
  • 2026-07-02: advisory: GitHub Advisory published/reviewed

References

Related threats