Description
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and never inspects IPv6, so any host that lacks an A record passes a private-range check. Editor oEmbed proxy fetches an attacker-supplied URL server side and reflects a response body, so an authenticated admin-panel user (default role site_admin or higher) can read internal-only services and cloud metadata, including IAM credentials, using an IPv6 literal or a domain that carries only an AAAA record. This issue has been patched in version 1.0.8.6.
Published: 2026-10-01
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Sensitive data exposure and potential internal service exploitation via SSRF
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a server‑side request forgery that bypasses the CMS’s IPv4‑only validation routine, allowing an attacker to supply an IPv6 literal or a domain resolved only via AAAA records. The editor’s oEmbed proxy fetches the supplied URL server‑side and reflects the response body. An authenticated administrator (site_admin or higher) can thereby retrieve internal‑only services and cloud metadata, including IAM credentials, exposing sensitive information that could be leveraged for further compromise.

Affected Systems

The affected product is Vvveb.com CMS, all releases prior to 1.0.8.6. Users with administrator privileges on the site’s admin panel are at risk, while non‑privileged users cannot exploit this path.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity level. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation data. However, the requirement of an authenticated admin account means that attackers who obtain or guess valid credentials can execute the SSRF, potentially exfiltrating internal data or cloud identities. The risk is therefore moderate to high for systems with exposed admin panels and where internal services are not adequately protected.

Generated by OpenCVE AI on October 1, 2026 at 20:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Vvveb to version 1.0.8.6 or later, which patches the IPv6 validation bypass.
  • If an upgrade is not immediately possible, disable or restrict the editor oEmbed proxy endpoint for non‑administrator roles to prevent SSRF attempts.
  • Implement network segmentation and firewall rules to block outbound connections from the CMS to internal IP ranges, and enable user authentication controls such as multi‑factor authentication for site_admin accounts.

Generated by OpenCVE AI on October 1, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Givanz
Givanz vvveb
Vendors & Products Givanz
Givanz vvveb

Thu, 01 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and never inspects IPv6, so any host that lacks an A record passes a private-range check. Editor oEmbed proxy fetches an attacker-supplied URL server side and reflects a response body, so an authenticated admin-panel user (default role site_admin or higher) can read internal-only services and cloud metadata, including IAM credentials, using an IPv6 literal or a domain that carries only an AAAA record. This issue has been patched in version 1.0.8.6.
Title Vvveb: Server-side request forgery in Vvveb via IPv6 bypass of validateUrl() in editor oEmbed proxy
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T18:43:19.102Z

Reserved: 2026-06-16T16:44:00.623Z

Link: CVE-2026-55232

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T19:17:21.900

Modified: 2026-10-01T19:17:23.117

Link: CVE-2026-55232

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T21:00:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)