Summary
CVE-2026-81889 is a Server-Side Request Forgery (SSRF) vulnerability in Studio-42’s elFinder, a widely used open-source web file manager, affecting versions prior to 2.1.70. The flaw allows a remote, unauthenticated attacker to bypass elFinder’s URL-upload address validation using DNS rebinding, causing the server to fetch and store content from internal or restricted network resources. The issue carries a High severity rating (CVSS 8.6).
Technical details
- Root cause: elFinder’s URL upload feature validates the resolved IP address via
validate_address(), but when PHP’s cURL extension is unavailable, the fallbackget_remote_contents()usesfsock_get_contents(), which performs a second, independent DNS resolution of the hostname when actually connecting. - This time-of-check-to-time-of-use (TOCTOU) gap lets an attacker control DNS responses (DNS rebinding) so the first resolution returns a public IP (passing validation) while the second resolution, used for the actual connection, returns a loopback or private/internal address.
- A secondary blind SSRF path exists via
get_headers($url, true), which independently re-resolves and requests the original hostname without reusing the validated/pinned connection — this occurs even when the cURL-based path is used. - Attack vector: Network, no authentication or user interaction required (
AV:N/AC:L/PR:N/UI:N); exploited by submitting a crafted URL to elFinder’s URL-upload connector command. - Impact: The internal HTTP response body fetched from the internal target is stored as an uploaded file and made readable through elFinder, exposing internal services, loopback endpoints, or other network-restricted resources (confidentiality impact only, no integrity/availability impact).
Affected software
- Studio-42 elFinder: all versions prior to 2.1.70
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Upgrade elFinder to version 2.1.70 or later, which fixes both the fallback socket DNS-rebinding gap and the unpinned
get_headers()request path. - If immediate patching is not possible:
- Disable or restrict the URL-upload feature in the elFinder connector configuration.
- Ensure the PHP cURL extension is installed and enabled, and, where possible, harden it to disallow redirects to private/internal address ranges.
- Apply network-level egress controls (e.g., firewall/proxy rules) preventing the application server from reaching loopback, link-local, and internal RFC1918 address ranges.

