Skip to main content
QUIETLYTIC
Vulnerability

Monsta FTP SSRF (CVE-2026-60105)

CVE-2026-60105 is a CVSS 8.6 SSRF in Monsta FTP via an IP-blocklist bypass, reported exploited by VulnCheck alone.

CVE-2026-60105
Threat Level
HIGH
CVSS
8.6
Status
Active Exploitation
Confidence
Medium
Affected Products
Monsta FTP (before 2.14.5)

CVE-2026-60105 carries a CVSS 3.1 base score of 8.6 against Monsta FTP, a web-based FTP client. NVD classifies it as CWE-918 (Server-Side Request Forgery) and states the flaw is fixed in version 2.14.5, meaning all earlier versions are affected. VulnCheck’s KEV feed reports the CVE as exploited, dated September 7, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-60105 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description locates the flaw in Monsta FTP’s fetchRemoteFile action, which is meant to block requests to internal/private IP ranges via an isBlockedIP() check. NVD states that check has a gap: it fails to detect IPv4 addresses embedded inside IPv4-mapped IPv6 address notation, an address format that represents an ordinary IPv4 address using an IPv6-style prefix. An unauthenticated attacker can retrieve a CSRF token from Monsta FTP’s public getSystemVars endpoint, then submit a request using that mapped-address format to cause the server to issue HTTP requests to internal services on the attacker’s behalf, with the response data written to an attacker-controlled FTP destination. NVD’s description explicitly calls out cloud instance metadata endpoints as a reachable target, which typically expose temporary cloud credentials to anything that can query them from inside the network.

We are reporting the class of bypass NVD describes and its impact, not the specific request format needed to reproduce it.

Evidence and confidence

  • Medium confidence — the CVSS 8.6 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N), the CWE-918 classification, the fixed version (2.14.5), and the described bypass mechanism all trace to NVD alone in our current ingestion, corroborated by VulnCheck’s own published advisory and blog post on the same flaw. The exploitation report traces to VulnCheck KEV alone.
  • Above-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.0186, a 78.2nd percentile score as of our ingestion.

No field is in conflict between our two sources.

Why this matters

SSRF vulnerabilities that reach cloud instance metadata services are a well-established path to full account or infrastructure compromise, since metadata endpoints frequently hand out temporary credentials scoped to whatever role the affected server runs under — no additional authentication needed once the attacker’s request reaches that endpoint. The fact that this bypass requires no authentication and only a correctly formatted address string, per NVD’s description, makes any internet-facing Monsta FTP deployment running a pre-2.14.5 version a meaningful target regardless of how well-configured its other access controls are.

Frequently Asked Questions

What is CVE-2026-60105? A CVSS 8.6 server-side request forgery vulnerability (CWE-918) in Monsta FTP before version 2.14.5, caused by an IP blocklist that fails to detect IPv4 addresses embedded in IPv4-mapped IPv6 notation, allowing unauthenticated attackers to reach internal services and cloud metadata endpoints.

Is CVE-2026-60105 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 7, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.

Do I need an account to exploit this? No. NVD’s description states an unauthenticated attacker can retrieve the required CSRF token from a public endpoint and submit the malicious request without any credentials.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Version 2.14.5, per NVD.


Severity, vector, weakness classification, and the described bypass mechanism sourced from the National Vulnerability Database record for CVE-2026-60105, corroborated by VulnCheck’s own advisory and blog post. Exploitation status and the September 7, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools