NONE · 0

CVE-2026-40500

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. The "Add Module from URL" feature requires superuser privileges (root-equivalent in ProcessWire) who already...

Vulnerability Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. The "Add Module from URL" feature requires superuser privileges (root-equivalent in ProcessWire) who already has unrestricted arbitrary code execution via standard module upload, making the SSRF vector incapable of providing incremental attack surface. The feature is also disabled by default and requires direct filesystem access to enable.

FAQ

What is CVE-2026-40500?

CVE-2026-40500 is a documented vulnerability. Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. The "Add Module from URL" feature requires superuser privileges (root-equivalent in ProcessWire) who already...

How severe is CVE-2026-40500?

CVSS scoring is not yet available for CVE-2026-40500. Check NVD for updates.

Is there a patch for CVE-2026-40500?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.