Description
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redirect, the redirected target URL bypasses the private IP address blacklist check. This allows authenticated users to scan and access internal network services. Version 2.18.2 contains a fix.
Published: 2026-09-08
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Internal network service access via SSRF
Action: Update to 2.18.2
AI Analysis

Impact

The vulnerability is a server‑side request forgery in the upload‑from‑URL feature. When the request follows an HTTP redirect, the CMS ignores its private‑IP blacklist, allowing authenticated users to force the server to issue requests to internal network addresses. This can reveal and expose services located behind firewalls, giving attackers knowledge and access to resources beyond the web perimeter. The flaw is a classic SSRF identified by CWE‑918.

Affected Systems

The affected product is Instantsoft ICMS2, versions earlier than 2.18.2. All installations of the open‑source CMS that have not applied the 2.18.2 update are vulnerable. The vendor announced a fix in commit 04b8fe0e and in the GitHub advisory.

Risk and Exploitability

The CVSS score of 3.1 indicates low overall severity, and the absence of an EPSS score and KEV listing means there is no evidence of widespread exploitation. Attackers must be authenticated to use the vulnerable upload feature, making the risk limited to the scope of legitimate user accounts. The SSRF can be triggered over the web interface, so the vulnerability is network‑accessible but requires valid credentials. Although the impact is limited, the ability to enumerate internal services may assist attackers in planning further attacks.

Generated by OpenCVE AI on September 8, 2026 at 18:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch by upgrading ICMS2 to version 2.18.2 or later.
  • If an upgrade is not immediately feasible, disable or remove the "upload from URL" functionality in the CMS configuration to block the SSRF path.
  • Limit user privileges so that only trusted administrators can access the upload feature, reducing the set of accounts that can trigger the flaw.

Generated by OpenCVE AI on September 8, 2026 at 18:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Instantcms
Instantcms icms2
Vendors & Products Instantcms
Instantcms icms2

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redirect, the redirected target URL bypasses the private IP address blacklist check. This allows authenticated users to scan and access internal network services. Version 2.18.2 contains a fix.
Title InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanning
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Instantcms Icms2
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-11T20:51:19.465Z

Reserved: 2026-05-22T18:47:27.755Z

Link: CVE-2026-48707

cve-icon Vulnrichment

Updated: 2026-09-11T20:51:10.847Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T18:17:38.167

Modified: 2026-09-11T21:17:10.250

Link: CVE-2026-48707

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:15:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)