PT-2026-97500 · Formie · Formie

CVE-2026-76086

·

Published

2026-07-17

·

Updated

2026-09-29

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Formie versions prior to 2.2.23 Formie versions prior to 3.1.31
Description An authenticated attacker can access the formie/integrations/form-settings control panel action within the IntegrationsController::actionFormSettings function without the necessary form integration permissions. By providing malicious request-supplied settings via the setAttributes() function, an attacker can overwrite outbound host properties such as apiUrl. This allows the server to send stored API keys or OAuth tokens to an attacker-controlled or internal host and return the remote response, resulting in a non-blind Server-Side Request Forgery (SSRF). SSRF is a vulnerability where a server is tricked into making requests to an unintended location. Sites allowing low-privileged or front-end user authentication are susceptible to the exfiltration of integration credentials and internal network probing.
Recommendations Update to version 2.2.23. Update to version 3.1.31. Restrict front-end user registration and limit control panel access as a temporary measure.

Exploit

Fix

Missing Authorization

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76086
GHSA-CVPC-HCCG-WMW4
GHSA-V3F3-CMJ4-CVJ9

Affected Products

Formie