Cross-Site Request Forgery Vulnerability in MobSF Mobile Application Security Tool
CVE-2026-68923
6.5MEDIUM
What is CVE-2026-68923?
A vulnerability in the MobSF mobile application security testing tool allows remote attackers to exploit the application by leveraging an absence of the CSRF protection middleware in active settings. This oversight permits attackers to craft malicious requests that could manipulate a victim's session without their consent. As a result, a logged-in user could unintentionally perform sensitive actions, such as deleting scans, altering passwords, and managing user accounts. This weakness affects MobSF versions prior to 4.5.1, where the issue has been addressed and resolved.
Affected Version(s)
Mobile-Security-Framework-MobSF < 4.5.1
