PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40500 processwire CVE debrief

CVE-2026-40500 is a server-side request forgery vulnerability in ProcessWire CMS versions 3.0.255 and prior. The vulnerability exists in the admin panel's 'Add Module From URL' feature, allowing authenticated administrators to supply arbitrary URLs to the module download parameter. This causes the server to issue outbound HTTP requests to attacker-controlled internal or external hosts. Attackers can exploit differentiable error messages returned by the server to perform reliable internal network port scanning, host enumeration across RFC-1918 ranges, and potential access to cloud instance metadata endpoints.

Vendor
processwire
Product
Unknown
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-15
Original CVE updated
2026-07-09
Advisory published
2026-04-15
Advisory updated
2026-07-09

Who should care

Administrators and security teams responsible for ProcessWire CMS installations should be aware of this vulnerability. Given the medium CVSS score of 6.1, organizations using affected versions should prioritize patching to prevent potential exploitation.

Technical summary

The vulnerability is caused by the 'Add Module From URL' feature in the ProcessWire CMS admin panel. Authenticated administrators can provide arbitrary URLs, leading to outbound HTTP requests to attacker-controlled hosts. This can result in internal network port scanning, host enumeration, and potential access to cloud instance metadata. The CVSS:4.0 vector is AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.

Defensive priority

Medium priority should be given to patching this vulnerability, as it allows for potential reconnaissance and exploitation of internal networks.

Recommended defensive actions

  • Apply patches or updates to ProcessWire CMS versions 3.0.255 and prior.
  • Restrict access to the 'Add Module From URL' feature in the admin panel.
  • Monitor server logs for suspicious outbound HTTP requests.
  • Implement additional security measures such as web application firewalls (WAFs) to detect and prevent exploitation attempts.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record was published on 2026-04-15T22:17:22.377Z and last modified on 2026-07-07T19:16:51.380Z. The NVD entry is currently Deferred. Limited details are available about the specific affected versions and scope of exploitation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-40500 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-40500

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-40500 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40500

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.