Cross-Site Request Forgery Vulnerability in Emlog Website Building System
CVE-2026-73847
6.8MEDIUM
What is CVE-2026-73847?
Emlog is a popular open-source website building platform that has a security flaw due to inadequate CSRF protection in the admin interface's AI Assistant feature. This vulnerability allows remote attackers to submit malicious requests to a logged-in administrator's session without needing authentication. The lack of a SameSite attribute on the authentication cookie and the handling of SQL queries exacerbate the risk, enabling attackers to potentially read, manipulate, and compromise database information. No fix has been issued for this security issue as of this moment, making it critical for users to be aware of the risks associated with using Emlog versions 2.6.26 and earlier.
Affected Version(s)
emlog <= 2.6.26
