Unrated severityNVD Advisory· Published Aug 4, 2026
RackTables cross-site request forgery
CVE-2026-18819
Description
A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project maintainer confirms: "[I]t seems plausible, in that RackTables does not at this time have any CSRF prevention. You may assign a CVE ID to this, but there is no guarantee it will be handled in urgent, or even timely, manner, or at all."
Affected products
1- Range: <=0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd
Patches
Vulnerability mechanics
References
6- github.com/fa1c4/security-advisories/tree/main/RackTables/PoCmitreexploit
- vuldb.com/cve/CVE-2026-18819mitrethird-party-advisory
- vuldb.com/submit/857970mitrethird-party-advisory
- github.com/fa1c4/security-advisories/blob/main/RackTables/RackTables_CSRF_report.mdmitrerelated
- vuldb.com/vuln/385818mitrevdb-entry
- vuldb.com/vuln/385818/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.