Cross-Site Request Forgery Vulnerability in MobSF Mobile Application Security Tool
CVE-2026-68923

6.5MEDIUM

Key Information:

Vendor

Mobsf

Vendor
CVE Published:
18 August 2026

What is CVE-2026-68923?

A vulnerability in the MobSF mobile application security testing tool allows remote attackers to exploit the application by leveraging an absence of the CSRF protection middleware in active settings. This oversight permits attackers to craft malicious requests that could manipulate a victim's session without their consent. As a result, a logged-in user could unintentionally perform sensitive actions, such as deleting scans, altering passwords, and managing user accounts. This weakness affects MobSF versions prior to 4.5.1, where the issue has been addressed and resolved.

Affected Version(s)

Mobile-Security-Framework-MobSF < 4.5.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.