Back

MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component

Published May 29, 2026

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing requests to arbitrary internal or external destinations.

Affected products

Remediation

Vendor solution

There are no official workarounds. To completely mitigate the exposure without upgrading, disabling or limiting external network access from the Mautic web server to internal-only subnets and local hosts is recommended.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mautic
Published May 29, 2026
Updated May 29, 2026
Reserved May 26, 2026
CISA Vulnrichment
Updated May 29, 2026
NVD
Status Deferred
Modified Jul 21, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Mautic
Published May 29, 2026
Updated May 29, 2026
Exploited since n/a
EUVD-2026-33273 GHSA-JMV8-8J9J-RCPC