PatchSiren

aimeos CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW aimeos CVE published 2026-08-12

CVE-2026-49262

Aimeos Pagible content management system versions prior to 0.10.4 contain a Server-Side Request Forgery (SSRF) vulnerability via DNS Rebinding in the administrative proxy route (cmsproxy). A Time-of-Check to Time-of-Use (TOCTOU) race condition allows attackers to access internal network resources and cloud metadata endpoints. The vulnerability is caused by a weakness in the URL validation phase, which can [truncated]