{"id":"CVE-2026-44925","title":"Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VI…","summary":"Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VI…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-352"],"vendor":"veritas","product":"infoscale_operations_manager","affected":["infoscale_operations_manager < 9.1.3"],"patched":["infoscale_operations_manager 9.1.3"],"published":"2026-05-20","updated":"2026-07-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-44925","references":[{"url":"https://supportinfoscale.cloud.com/support-home/kbsearch/article?articleNumber=1000766080&articleTitle=InfoScale_Operations_Manager_IOM_web_application_Security_Bulletin_for_CVE_2026_44923_CVE_2026_44924_and_CVE_2026_44925","label":"cve@mitre.org"},{"url":"https://www.veritas.com/support/en_US/doc/120571566-166757640-0/viom_tot_v118836641-166757640","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.00198,"epssPercentile":0.09916,"ingestedAt":"2026-07-23T12:17:55.411Z","slug":"CVE-2026-44925","body":"## Overview\n\nCross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge.\n\n## Affected\n\n- `infoscale_operations_manager < 9.1.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `infoscale_operations_manager 9.1.3`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}