VYPR
High severity8.1NVD Advisory· Published Sep 16, 2026

CVE-2026-92751

CVE-2026-92751

Description

CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft hidden forms that submit to destructive endpoints like topic deletion and cluster configuration changes, leveraging the operator's HTTP Basic authentication credentials or play-basic-authentication cookie without SameSite protection.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Yahoo/Cmakreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=3.0.0.6

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.