CVE-2026-33486: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33486 is a Server-Side Request Forgery (SSRF) and Local File Inclusion (LFI) vulnerability in the roadiz/documents Composer package, specifically in the RZ\Roadiz\Documents\DownloadedFile::fromUrl() component of the Roadiz CMS. It allows an authenticated attacker with ROLE_ACCESS_DOCUMENTS permission to read arbitrary files from the server's local file system, including .env files, database credentials, and internal configuration files. The vulnerability affects roadiz/documents versions prior to 2.3.42, 2.5.44 (for the 2.4–2.5 branch), 2.6.28, and 2.7.9. It was published on March 22, 2026, and has a CVSS v3.1 base score of 6.8 (Moderate) per the GitHub Advisory, or 6.5 (Medium) per NVD scoring (GitHub Advisory, Roadiz Advisory).

Technical details

The root cause is CWE-918 (Server-Side Request Forgery): the $url parameter in DownloadedFile::fromUrl() is passed directly to PHP's native fopen() function without any scheme validation or sanitization. Because PHP's stream wrappers support file:// URIs natively, an attacker can supply a file:///app/.env or similar URI, causing the application to read local files and store them as documents in the publicly accessible Media Library. The attack vector is network-based and exploited through the Podcast RSS Feed importer or OEmbed media import features — an attacker crafts a malicious XML feed containing an itunes:image href="file:///app/.env" attribute, which the AbstractPodcastFinder processes and passes to the vulnerable function. A detailed proof-of-concept with step-by-step reproduction instructions is publicly available in the security advisory (GitHub Advisory, Patch Commit).

Impact

Successful exploitation results in a total loss of confidentiality for the web application and potentially the underlying host. An attacker can exfiltrate sensitive files such as .env (containing API keys, APP_SECRET, and database credentials), security.yaml, SQLite database files, and /etc/passwd for system user enumeration. In cloud-hosted deployments (AWS, Azure, GCP), the SSRF vector can be extended to query internal metadata endpoints (e.g., http://169.254.169.254/latest/meta-data/), potentially enabling theft of IAM credentials and full cloud infrastructure compromise. There is no integrity or availability impact, but the confidentiality breach can enable complete horizontal and vertical privilege escalation (Roadiz Advisory).

Exploitability

A public proof-of-concept with concrete step-by-step exploitation instructions is available in the GitHub Security Advisory, classified as a high-confidence, real exploit by Feedly threat intelligence. Exploitation requires authentication with ROLE_ACCESS_DOCUMENTS privileges, which limits the attack surface but does not eliminate risk from insider threats or compromised accounts. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.026% (2nd percentile), indicating a low current probability of exploitation in the wild (GitHub Advisory, Roadiz Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Roadiz CMS instance running a vulnerable version of roadiz/documents (< 2.3.42, < 2.5.44, < 2.6.28, or < 2.7.9). Obtain or compromise credentials for an account with ROLE_ACCESS_DOCUMENTS permission.
  2. Craft the malicious payload: Create a Podcast RSS XML feed (podcast.xml) hosted on an attacker-controlled server. Inject a file:// URI into the itunes:image href attribute targeting a sensitive file:
<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">
  <channel>
    <title>Roadiz LFI Exploit</title>
    <itunes:image href="file:///app/.env"/>
  </channel>
</rss>
  1. Trigger the import: Authenticate to the Roadiz Backoffice. Navigate to Documents (Media Manager) → Add a document → Import from URL (or trigger a Podcast sync). Supply the URL pointing to the malicious podcast.xml file.
  2. Extract the data: The AbstractPodcastFinder processes the XML and passes file:///app/.env to DownloadedFile::fromUrl(). PHP's fopen() reads the local file and stores its contents as a new Document in the Media Library (appearing as a broken image icon).
  3. Download the exfiltrated file: Navigate to the Media Manager dashboard, locate the newly created document, and download it to retrieve the contents of .env, including database credentials, APP_SECRET, and API keys.
  4. Pivot (optional): Repeat with other targets such as file:///etc/passwd, file:///app/config/security.yaml, or cloud metadata endpoints (http://169.254.169.254/latest/meta-data/) to escalate further (Roadiz Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the web server to attacker-controlled domains serving malicious XML/RSS feeds; requests to internal cloud metadata endpoints (e.g., 169.254.169.254) originating from the PHP web process.
  • Logs: Web server or application logs showing document import requests with external URLs pointing to unusual or attacker-controlled domains; PHP error logs referencing fopen() calls with file:// URIs (on unpatched systems).
  • File System: Unexpected files appearing in the Roadiz Media Library/Documents storage directory with content matching sensitive system files (e.g., .env contents, /etc/passwd format); temporary files in the PHP temp directory with names derived from sensitive file paths.
  • Application: New documents appearing in the Roadiz Media Manager with broken image icons and file sizes consistent with configuration files; document import history showing URLs to external RSS/XML feeds not associated with legitimate podcast sources (Roadiz Advisory).

Mitigation and workarounds

Upgrade the roadiz/documents Composer package to one of the following patched versions: 2.3.42 (for the 2.3.x branch), 2.5.44 (for the 2.4–2.5 branches), 2.6.28 (for the 2.6.x branch), or 2.7.9 (for the 2.7.x branch). The fix adds a isSafeRemoteUrl() validation method that restricts fopen() calls to http:// and https:// schemes only, blocks private/reserved IP ranges, and rejects localhost hostnames. As interim mitigations: restrict ROLE_ACCESS_DOCUMENTS to only trusted users with a legitimate business need; implement network-level egress filtering to block outbound requests from the web server to internal IP ranges and cloud metadata endpoints; and monitor Media Library activity for unexpected document imports (GitHub Advisory, Patch Commit).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management