What the CVE Entry Establishes
The disclosure identifies an unauthenticated privilege-escalation flaw in Amelia Premium versions 8.0 through 9.6.2. The customer update endpoint does not sufficiently validate the attacker-controlled `type` parameter. An attacker can select the manager type and set `externalId` to 0, causing creation of a WordPress account with the `wpamelia-manager` role. That role opens the second stage: creating a provider entity linked to an existing administrator user ID and overwriting the administrator's password. The result is administrator access without valid prior credentials. The entry does not specify an HTTP method, request format, source filename, or fixed version, so this article does not invent those details. Researcher d.v4n_s3c is credited with the finding.
BitFire FREE Blocks Automated Endpoint Abuse
The disclosed chain depends on interaction with Amelia's customer update endpoint, a restricted action that changes account state. BitFire FREE Bot Protection blocks known attack and scanning tools and prevents unknown or restricted bots from calling sensitive endpoints or submitting data before vulnerable plugin code runs. A client presenting as a browser must pass lightweight JavaScript verification before restricted actions; ordinary browsers normally pass, while scripts and fake browsers often fail. This directly blocks automated exploit delivery governed by that policy. It does not repair Amelia's missing validation, and an explicitly allowed bot or successfully verified client is not claimed to be stopped at this layer. Commercial sites require the appropriate BitFire license.
BitFire PRO RASP Stops Protected Takeover Outcomes
BitFire PRO RASP enforces authorization when WordPress and PHP attempt protected operations. Its database protection blocks unauthorized user creation, privilege escalation, administrator-role assignment, and protected data changes. In this chain, RASP can deny the unauthorized creation or promotion associated with the manager step and block the later attempt to overwrite an administrator's password through a provider linked to that administrator's user ID. This enforcement is based on the requester's authority at the protected operation. RASP does not sanitize `type`, change `externalId`, or claim to prevent the vulnerable endpoint from being reached; it blocks the covered privileged results that turn the validation failure into account takeover.
If Your Site Was Affected, Investigate for Persistence.
Update Amelia immediately to a release the vendor identifies as fixed; the supplied disclosure does not name a fixed version. Patching closes the known path but cannot reverse an earlier password change or remove persistence established after takeover. Run BitFire Threat Hunter to look for backdoor WordPress administrator accounts, hidden database triggers, WordPress and server cron persistence, suspicious database content, long-running PHP processes, and droppers that can restore malware or reinfect the site. Review Amelia customer, manager, and provider records for unexpected links to WordPress users. Remove every malicious account and persistence mechanism found, restore affected administrator access safely, and rotate relevant credentials. An absence of obvious malicious files does not prove the site is clean.
Deploy Layered BitFire Protection Now
CVE-2026-9055 turns weak endpoint validation into an unauthenticated administrator-takeover path. Enable BitFire Bot Protection to stop automated abuse before Amelia processes restricted actions, and deploy BitFire PRO RASP to deny unauthorized role, user, password, and administrator outcomes at runtime. Then install a vendor-confirmed fixed Amelia release and investigate every site that ran versions 8.0 through 9.6.2. Use Threat Hunter wherever prior exposure is possible. BitFire provides decisive delivery blocking, runtime containment, and post-compromise investigation without treating security controls as a substitute for patching.