OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-76086: Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials

GitHub Advisories · officialPublished Sep 23, 2026Risk 37/100

### Impact The control panel action `formie/integrations/form-settings` (`IntegrationsController::actionFormSettings`) was reachable by any authenticated user without the appropriate form integration permissions. The action applied request-supplied settings to a fully configured integration via `setAttributes($settings, false)`, allowing an attacker to overwrite outbound host properties (e.g. `apiUrl`) while the server sent stored API keys or OAuth tokens to the attacker-controlled host. The remote response was returned in the JSON body (non-blind SSRF). This is an incomplete remediation of [GHSA-cvpc-hccg-wmw4](https://github.com/advisories?query=GHSA-cvpc-hccg-wmw4). The `form-settings` action was excluded from the permission gate added in 3.1.28. Any site where a low-privileged user can authenticate (including front-end members on sites with public registration) could exfiltrate CRM/email-marketing/webhook integration credentials and probe internal network endpoints. ### Patches Fixed in **3.1.31** (Craft 5) and **2.2.23** (Craft 4). The action now requires a CP request, a valid `formId`, and form integration permissions (`formie-showFormIntegrations` / per-form variant on Craft 5; `formie-manageFormIntegrations` / per-form variant on Craft 4). Request settings are filtered to an allowlist; URL, host, and credential properties cannot be overridden from user input. ### Workarounds Restrict front-end user registration and limit CP access until upgraded. No configuration-only workaround fully mitigates the issue. - Reported by Jorge González ([email protected])

Upgrade affected packages to a patched version: verbb/formie 3.1.31, verbb/formie 2.2.23.

Vendor
Not specified
Product
verbb/formie
Exploitation
none known
Evidence
official
CVSS
8.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source