CVE-2026-40500
Summary
| CVE | CVE-2026-40500 |
|---|---|
| State | REJECTED |
| Assigner | VulnCheck |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-15 22:17:22 UTC |
| Updated | 2026-07-09 23:17:05 UTC |
| Description | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. The "Add Module from URL" feature requires superuser privileges (root-equivalent in ProcessWire) who already has unrestricted arbitrary code execution via standard module upload, making the SSRF vector incapable of providing incremental attack surface. The feature is also disabled by default and requires direct filesystem access to enable. |
Risk And Classification
EPSS: 0.003850000 probability, percentile 0.305330000 (date 2026-07-09)
There are no known software configurations currently associated with this CVE in NVD or the CVE Program record.
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| gist.github.com/thepiyushkumarshukla/7514e5eed526fd9d20fcfc42ce8d0a82 | MITRE | gist.github.com | |
| processwire.com | MITRE | processwire.com | |
| www.vulncheck.com/advisories/processwire-cms-ssrf-via-add-module-from-url | MITRE | www.vulncheck.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.