CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-52840

lowCVSS 2.7covered by 2 sourcesfirst seen 2026-07-14
Summary Caldav::connect_to_server at application/controllers/Caldav.php:60 hands the request's caldav_url to a Guzzle REPORT call without scheme or host validation. A logged-in backend user (admin, provider, or secretary) reaches loopback, RFC1918, and link-local hosts on the deployment's network. The Guzzle exception path returns the upstream status code plus ~120 bytes of response body in the JSON message field (Caldav.php:74-78), so the SSRF is semi-blind. Preconditions - Backend login on the target instance. Non-admin attackers supply their own provider_id and pass the per-row check at Caldav.php:52; admins can target any row. - Default deployment per the project's own docker-compose.yml, which puts mysql, mailpit, phpmyadmin, baikal, openldap, phpldapadmin, and swagger-ui on the same docker network as php-fpm. Details // application/controllers/Caldav.php:45-82 public function connect_to_server(): void { try { $provider_id = request('provider_id'); $user_id = session('user_id'); if (cannot('edit', PRIV_USERS) && (int) $user_id !== (int) $provider_id) { throw new RuntimeException('You do not have the required permissions for this task.'); } $caldav_url = request('caldav_url'); // (*) attacker-controlled $caldav_username = request('caldav_username'); $caldav_password = request('caldav_password'); $this->caldav_sync->test_connection($caldav_url, $caldav_username, $caldav_password); // (*) sink ... } catch (GuzzleException | InvalidArgumentException $e) { json_response([ 'success' => false, 'message' => $e->getMessage(), // (*) upstream body reflected ]); } } The per-row check at line 52 only constrains *which provider record* the caller may write to; it does not constrain *where the outbound request lands*. $caldav_url flows unchanged into Caldav_sync::test_connection at application/libraries/Caldav_sync.php:389, which calls get_http_client to construct a Guzzle client whose base_uri is the attacker URL (Caldav_sync.php:375-382), then issues REPORT agains

⚡ Watch CVE-2026-52840

Get an email if CVE-2026-52840 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-52840

CVE.org record

Embed the live status

CVE-2026-52840 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-52840 status](https://www.csirts.com/badge/CVE-2026-52840)](https://www.csirts.com/cve/CVE-2026-52840)