CVE-2026-43936: e107: Server-Side Request Forgery (SSRF) in the remote file fetcher
e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from "Image/File URL:" of "From a remote location" in "Media Manager" on the administrator screen. This vulnerability is fixed in 2.3.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
e107to a version that resolves this vulnerability.Fixed in 2.3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43936?
The severity of CVE-2026-43936 is classified as medium with a score of 4.3.
How do I fix CVE-2026-43936?
To fix CVE-2026-43936, upgrade to e107 version 2.3.4 or later.
What does CVE-2026-43936 affect?
CVE-2026-43936 affects the e107 content management system prior to version 2.3.4.
What type of vulnerability is CVE-2026-43936?
CVE-2026-43936 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
Can CVE-2026-43936 be exploited remotely?
Yes, CVE-2026-43936 can be exploited remotely through the media manager in the e107 CMS.