A vulnerability was found in e107 CMS up to 2.3.3. It has been declared as critical. Affected is an unknown function. Such manipulation leads to server-side request forgery.

This vulnerability is uniquely identified as CVE-2026-43936. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.