CVE-2026-73847
Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently logged-in administrator. The authentication cookie set in include/lib/loginauth.php has no explicit SameSite attribute, enabling Chrome's temporary Lax+POST grace window. The query_database case passes attacker-controlled sql and confirm_code values to Ai::queryDatabase in include/service/ai.php; read queries need no confirmation, write queries accept the public confirm string, only the blog table is write-protected, and aliasing password as pwd_hash bypasses output redaction. A successful request can read every database table and write every table except blog, including changing the user table to take over an administrator account. No fixed version is available as of this review.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- EPSS probability
- 0.20%
- CWE
- CWE-352, CWE-798, CWE-1275
- Published
- 2026-08-14
- Last modified
- 2026-08-14
Affected products
- emlog emlog
Weakness type
Related vulnerabilities
- CVE-2026-80380 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-84432 — Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog controller
- CVE-2026-88061 — career-ops: Local dashboard API accepted cross-origin and non-loopback requests, allowing unauthenticated command execution
- CVE-2026-88873 — WWBN AVideo Cross-Site Request Forgery via logArchive.json.php
- CVE-2026-88872 — AVideo CustomizeUser setPassword.json.php CSRF
- CVE-2026-88871 — WWBN AVideo CustomizeUser setSubscribers CSRF via GET
- CVE-2026-88870 — WWBN AVideo LoginControl PGP Key CSRF via GET Request
- CVE-2026-78083 — Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4