No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 05 Sep 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services, and perform network reconnaissance on the instance infrastructure. | |
| Title | Webstudio through 0.296.0 SSRF via /cgi proxy routes | |
| First Time appeared |
Webstudio
Webstudio ultimate Loan Manager |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:webstudio:ultimate_loan_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webstudio
Webstudio ultimate Loan Manager |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-24T14:21:06.231Z
Reserved: 2026-09-05T01:59:22.058Z
Link: CVE-2026-86119
Updated: 2026-09-18T17:18:21.763Z
Status : Deferred
Published: 2026-09-05T10:16:43.157
Modified: 2026-09-24T21:08:55.030
Link: CVE-2026-86119
No data.
OpenCVE Enrichment
Updated: 2026-09-05T13:00:05Z