Cross-Site Request Forgery Protection Bypass in Rodauth by Jeremy Evans
CVE-2026-82468

4.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 August 2026

What is CVE-2026-82468?

Rodauth versions prior to 2.47.0 are susceptible to a serious vulnerability that allows attackers to bypass cross-site request forgery (CSRF) protection. This flaw occurs due to inadequate validation of JSON request content types, enabling attackers to craft malicious cross-origin form posts containing specific application/json substrings. As a result, victims may unknowingly authenticate to accounts controlled by the attacker, exposing sensitive information and leading to further attacks. It is crucial for users to upgrade to the latest version to mitigate this risk.

Affected Version(s)

rodauth 0 < 2.47.0

References

CVSS V4

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joshua Rogers (AISLE Research)
.