Cross-Site Request Forgery in CMAK by Yahoo
CVE-2026-92751

7.2HIGH

Key Information:

Vendor

Yahoo

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92751?

CMAK versions up to 3.0.0.6 are susceptible to a Cross-Site Request Forgery attack due to the absence of a CSRF filter. This vulnerability allows attackers to execute unauthorized actions on behalf of users with authenticated sessions. By crafting hidden forms targeting sensitive endpoints, such as those for cluster configuration changes and topic deletions, malicious actors can leverage users' HTTP Basic authentication credentials or cookies that lack SameSite protection. This oversight significantly jeopardizes the integrity of user operations within the application.

Affected Version(s)

CMAK 0 <= 3.0.0.6

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.