Cross-Site Request Forgery in Cotonti Affects User Group Management
CVE-2026-101093

5.3MEDIUM

Key Information:

Vendor

Cotonti

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101093?

Cotonti, up to version 1.0.0, is susceptible to a cross-site request forgery (CSRF) vulnerability found in the admin.users.php file. This flaw permits attackers to execute unauthorized actions, specifically enabling the deletion of user groups without proper token verification. By ingeniously crafting malicious links or web pages, an attacker can trick authenticated administrators into unwittingly executing the deletion of custom user groups, along with their associated permissions, while leveraging the administrator's active session. Organizations utilizing Cotonti should promptly implement the necessary security measures to mitigate this risk.

Affected Version(s)

Cotonti 0 <= 1.0.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.