Description
Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-time-of-use race conditions and shared address space bypasses to access internal network resources and exfiltrate image content.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a server‑side request forgery in the cors‑proxy endpoint of Docs version 5.6.1. Attackers can supply a public document UUID to cause the server to perform outbound HTTP requests, potentially reaching internal network resources and retrieving sensitive image content. This flaw enables confidentiality and integrity compromise of internal systems and may facilitate further lateral movement. The weakness is categorized as CWE‑918.

Affected Systems

The affected product is Docs by suitenumerique, version 5.6.1. No later versions are listed as patched in the CVE data, so any deployment of the 5.6.1 release is vulnerable.

Risk and Exploitability

The CVSS score for this issue is 6.9, indicating a moderate severity vulnerability. The EPSS score is unavailable, so recent exploitation probability is unknown, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers can exploit the unprotected endpoint remotely; the likely attack vector is initiating a crafted HTTP request to the cors‑proxy endpoint to trigger the SSRF. Successful exploitation requires only unauthenticated access, meaning any external user can exploit the flaw without prior credentials.

Generated by OpenCVE AI on September 15, 2026 at 12:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Docs to a fixed version that addresses the SSRF flaw or apply the vendor‑supplied patch if available.
  • Restrict the cors‑proxy endpoint to require authentication, ensuring only authorized internal users can use it.
  • Block outbound connections from the Docs service to internal network ranges using firewall rules or network segmentation, limiting the potential impact of SSRF.
  • Restrict DNS resolution for the Docs service to public DNS only, mitigating DNS‑based time‑of‑check/time‑of‑use attacks.

Generated by OpenCVE AI on September 15, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Suitenumerique
Suitenumerique docs
Vendors & Products Suitenumerique
Suitenumerique docs

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-time-of-use race conditions and shared address space bypasses to access internal network resources and exfiltrate image content.
Title Docs through 5.6.1 SSRF via Unauthenticated cors-proxy Endpoint
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Suitenumerique Docs
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:09.421Z

Reserved: 2026-09-14T17:33:17.464Z

Link: CVE-2026-91081

cve-icon Vulnrichment

Updated: 2026-09-20T00:30:43.610Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:20:29.920

Modified: 2026-09-23T17:17:47.693

Link: CVE-2026-91081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T12:30:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)