PT-2026-94037 · Yahoo+1 · Cmak

·

CVE-2026-92751

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions CMAK versions prior to 3.0.0.7
Description The software fails to install a cross-site request forgery (CSRF) filter, which is a mechanism used to prevent unauthorized commands from being transmitted from a user that the web application trusts. This allows attackers to perform state-changing actions on behalf of authenticated operators by crafting hidden forms that submit to destructive endpoints, such as those used for topic deletion and cluster configuration changes. The attack leverages the operator's HTTP Basic authentication credentials or the play-basic-authentication cookie, which lacks SameSite protection.
Recommendations Update to version 3.0.0.7 or later.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92751

Affected Products

Cmak