LOW
aimeos
CVE published 2026-08-12
CVE-2026-49262
Aimeos Pagible content management system versions prior to 0.10.4 contain a Server-Side Request Forgery (SSRF) vulnerability via DNS Rebinding in the administrative proxy route (cmsproxy). A Time-of-Check to Time-of-Use (TOCTOU) race condition allows attackers to access internal network resources and cloud metadata endpoints. The vulnerability is caused by a weakness in the URL validation phase, which can [truncated]