What is CVE-2026-49262?
CVE-2026-49262 is a vulnerability in Aimeos Pagible CMS versions prior to 0.10.4 where the administrative proxy route (`cmsproxy`) allows Server-Side Request Forgery (SSRF) attacks via DNS Rebinding. This flaw exists due to a TOCTOU (Time-of-Check to Time-of-Use) race condition between URL validation and its use. Immediate update to version 0.10.4 is required to mitigate the risk.
Azərbaycanca: CVE-2026-49262, Aimeos Pagible CMS-in 0.10.4-dən əvvəlki versiyalarında inzibati proxy (`cmsproxy`) idxalından istifadə edərək, DNS Rebinding vasitəsilə Server-Side Request Forgery (SSRF) hücumuna yol açan bir təhlükəsizlik boşluğudur. Bu boşluq, URL doğrulaması ilə onun istifadəsi arasında TOCTOU (Time-of-Check to Time-of-Use) yarış şəraiti səbəbindən yaranır. Təsirə məruz qalan sistemlərdə təcili olaraq 0.10.4 versiyasına yeniləmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of Aimeos Pagible CMS are affected by CVE-2026-49262?
This vulnerability affects Aimeos Pagible CMS versions prior to 0.10.4.
What is the root cause of CVE-2026-49262?
The root cause is a TOCTOU (Time-of-Check to Time-of-Use) race condition between URL validation and its use within the `cmsproxy` administrative route.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.