PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18856 Poesis CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T01:16:44.757Z and has not been modified since then. The vulnerability affects Poesis Rhymix CMS up to version 2.1.33, specifically in the procImporterAdminCheckXmlFile function of the modules/importer/importer.admin.controller.php file. This server-side request forgery vulnerability allows remote attackers to manipulate the filename argument, potentially leading to unauthorized requests. The attack is possible to be carried out remotely. Upgrading to version 2.1.34 will fix this issue. Limited evidence is available from official CVE and NVD sources.

Vendor
Poesis
Product
Rhymix CMS
CVSS
LOW 2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-05
Original CVE updated
2026-08-05
Advisory published
2026-08-05
Advisory updated
2026-08-05

Who should care

Administrators and users of Poesis Rhymix CMS up to version 2.1.33 should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and restricting access to the Data Import Module, monitoring for suspicious activity, and upgrading to version 2.1.34 or later. Security teams and vulnerability management teams should also be aware of this vulnerability and track exceptions, retest remediated assets, and close the item only after evidence is documented.

Technical summary

The Poesis Rhymix CMS up to 2.1.33 contains a server-side request forgery vulnerability in the procImporterAdminCheckXmlFile function of the modules/importer/importer.admin.controller.php file. This allows remote attackers to manipulate the filename argument, potentially leading to unauthorized requests. The vulnerability was determined in Poesis Rhymix CMS up to 2.1.33, and upgrading to version 2.1.34 or later is recommended to fix this issue. The attack is possible to be carried out remotely, and limited details are available from official CVE and NVD sources.

Defensive priority

Low CVSS score of 2 indicates limited impact; however, server-side request forgery vulnerability in Poesis Rhymix CMS up to 2.1.33 requires attention.

Recommended defensive actions

  • Upgrade Poesis Rhymix CMS to version 2.1.34 or later
  • Review and restrict access to the Data Import Module
  • Monitor for suspicious activity related to server-side request forgery
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

Evidence from official CVE and NVD sources indicates a server-side request forgery vulnerability in Poesis Rhymix CMS up to 2.1.33; details are limited. The CVE record was published on 2026-08-05T01:16:44.757Z and has not been modified since then. The vulnerability affects the procImporterAdminCheckXmlFile function of the modules/importer/importer.admin.controller.php file. The attack is possible to be carried out remotely. Upgrading to version 2.1.34 will fix this issue.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T01:16:44.757Z and has not been modified since then.