PT-2026-97500 · Formie · Formie
CVE-2026-76086
·
Published
2026-07-17
·
Updated
2026-09-29
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Formie versions prior to 2.2.23
Formie versions prior to 3.1.31
Description
An authenticated attacker can access the
formie/integrations/form-settings control panel action within the IntegrationsController::actionFormSettings function without the necessary form integration permissions. By providing malicious request-supplied settings via the setAttributes() function, an attacker can overwrite outbound host properties such as apiUrl. This allows the server to send stored API keys or OAuth tokens to an attacker-controlled or internal host and return the remote response, resulting in a non-blind Server-Side Request Forgery (SSRF). SSRF is a vulnerability where a server is tricked into making requests to an unintended location. Sites allowing low-privileged or front-end user authentication are susceptible to the exfiltration of integration credentials and internal network probing.Recommendations
Update to version 2.2.23.
Update to version 3.1.31.
Restrict front-end user registration and limit control panel access as a temporary measure.
Exploit
Fix
Missing Authorization
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Formie