---
id: CVE-2026-101093
title: >-
  Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in
  admin.users.php that allows attackers to delete user groups without token
  verification
summary: >-
  Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in
  admin.users.php that allows attackers to delete user groups without token
  verification. Attackers can craft malicious links or pages that trick
  authenticated ad…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'
cwe:
  - CWE-352
vendor: Cotonti
product: Cotonti
affected:
  - Cotonti <= 1.0.0
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T22:17:30.980'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101093'
references:
  - url: 'https://github.com/Cotonti/Cotonti'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Cotonti/Cotonti/blob/1.0.0/system/admin/admin.users.php#L136-L140
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Cotonti/Cotonti/issues/1907#issuecomment-5845691148'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Cotonti/Cotonti/pull/1908'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/cotonti-through-1.0.0-cross-site-request-forgery-via-user-group-deletion
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T22:22:13.608Z'
---

## Overview

Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft malicious links or pages that trick authenticated administrators into deleting custom groups and their associated permissions by riding the administrator's session.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
