Cross-Site Request Forgery Vulnerability in Emlog Website Building System
CVE-2026-73847

6.8MEDIUM

Key Information:

Vendor

Emlog

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-73847?

Emlog is a popular open-source website building platform that has a security flaw due to inadequate CSRF protection in the admin interface's AI Assistant feature. This vulnerability allows remote attackers to submit malicious requests to a logged-in administrator's session without needing authentication. The lack of a SameSite attribute on the authentication cookie and the handling of SQL queries exacerbate the risk, enabling attackers to potentially read, manipulate, and compromise database information. No fix has been issued for this security issue as of this moment, making it critical for users to be aware of the risks associated with using Emlog versions 2.6.26 and earlier.

Affected Version(s)

emlog <= 2.6.26

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.