CVE-2026-36469
9.1 CRITICALpublic exploit availablePublished 2026-09-21 · Updated 2026-09-24
AI risk analysis
- Summary
- CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) allowing attackers to forge requests and potentially access internal services or networks.
- Exploitability
- Exploitation requires the attacker to have the ability to trigger the 'Upload by URL' functionality, which may be difficult if the feature is not commonly used or restricted.
- Blast radius
- If exploited, attackers could gain access to internal services or networks, leading to significant data exposure or system compromise.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to a version of CuteNews that addresses this vulnerability, such as 2.1.3 or later.
ssrfwebuploadvulnerability
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality).
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-918
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-51994PoC
- MEDIUMCVE-2026-61749PoC
- HIGHCVE-2026-71270PoC
- HIGHCVE-2026-81999
- CRITICALCVE-2026-82000
- CRITICALCVE-2026-82013
- CRITICALCVE-2026-82443
- CRITICALCVE-2026-83660
Related by shared AI tags and CWE weakness class. Browse the full archive.