Threat Advisory

Formie Flaw Lets Attackers Exfiltrate Stored Integration Credentials

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting verbb/formie versions >= 3.0.0, < 3.1.31 affecting verbb/formie versions < 2.2.23 have been identified in Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials.

CVE-2026-76086 (CVSS 8.5 — Severity): The control panel action `` was reachable by any authenticated user without the appropriate form integration permissions, allowing an attacker to overwrite outbound host properties while the server sent stored API keys or OAuth tokens to the attacker-controlled host.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting verbb/formie versions >= 3.0.0, < 3.1.31 affecting verbb/formie versions < 2.2.23 have been identified in Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials.

CVE-2026-76086 (CVSS 8.5 — Severity): The control panel action `` was reachable by any authenticated user without the appropriate form integration permissions, allowing an attacker to overwrite outbound host properties while the server sent stored API keys or OAuth tokens to the attacker-controlled host.[emaillocker id="1283"]

CVE-2026-76087 (CVSS 8.2 — Severity): Unauthenticated users can enumerate sequential submission IDs and overwrite or hijack another user's in-progress submission via the anonymous front-end action ``. Tampered data could be persisted and forwarded via notifications and integrations when the submission was completed.

CVE-2026-76089: An unauthenticated attacker could exploit a vulnerability by submitting a malicious request to overwrite an existing, incomplete submission. The attack vector is not explicitly stated in the article.

RECOMMENDATION:

We recommend you to update verbb/formie to version 3.1.31 or 2.2.23.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu