CVE-2026-10581: DedeCMS download.php base64_decode server-side request forgery

Published Jun 2, 2026
·
Updated

A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64decode of the file /plus/download.php?open=1. This manipulation of the argument Link causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been published and may be used.

Affected Software

1 affected component
DedeCMS Dedecms=5.7.88

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove DedeCMS /plus/download.php from your environment.

    Remove or disable the /plus/download.php script (or the open=1 functionality) until a vendor-supplied patch is available to eliminate the SSRF vulnerability in DedeCMS 5.7.88.

  2. Configuration

    Disable or harden processing of the open=1 Link parameter in /plus/download.php: stop calling base64_decode on untrusted input, add strict validation to ensure the decoded value is not a URL or network address, or reject requests where Link decodes to an external/internal URL.

    DedeCMS /plus/download.php processing of open=1 Link parameter (base64_decode) = disable or validate
  3. Compensating control

    Apply network-level controls to prevent SSRF exploitation: block or restrict outbound HTTP(S) requests from the web server to internal and external hosts, and restrict access to /plus/download.php (open=1) to trusted IPs via firewall, WAF, or reverse proxy rules.

  4. Operational

    Search web server and application logs for attempts to call /plus/download.php?open=1 and for unusual outbound connections; if exploitation is suspected, contain and investigate affected hosts and rotate any credentials or secrets that could have been accessed via SSRF.

Event History

Jun 2, 2026
CVE Published
via MITRE·02:30 AM
Data Sourced
via MITRE·02:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-10581?

The severity of CVE-2026-10581 is classified as low with a score of 2.1.

2

How do I fix CVE-2026-10581?

To fix CVE-2026-10581, upgrade DedeCMS to a version that has addressed this vulnerability.

3

What type of attack is associated with CVE-2026-10581?

CVE-2026-10581 is associated with a server-side request forgery (SSRF) attack.

4

Which software is affected by CVE-2026-10581?

DedeCMS version 5.7.88 is affected by CVE-2026-10581.

5

Can CVE-2026-10581 be exploited remotely?

Yes, CVE-2026-10581 allows for remote exploitation of the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203