---
id: CVE-2026-58143
title: Cotonti Siena 0.9.26 CSRF via admin.php Config Update Endpoint
summary: >-
  Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery
  vulnerability that allows unauthenticated attackers to modify administrator
  configuration by tricking a logged-in administrator into submitting a forged
  POST request …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-352
vendor: Cotonti
product: Cotonti
affected:
  - Cotonti <= 0.9.26
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-07-10T14:40:45.545297Z'
exploitAvailable: true
published: '2026-07-09'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:20:06.578Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-58143'
references:
  - url: 'https://gist.github.com/sermikr0/75686815e441c07462cfdea2fed5d305'
    label: Researcher Disclosure
  - url: >-
      https://www.vulncheck.com/advisories/cotonti-siena-csrf-via-admin-php-config-update-endpoint
tags:
  - cve.org
  - exploit-available
epss: 0.00235
epssPercentile: 0.13125
ingestedAt: '2026-10-01T15:48:17.862Z'
---

## Overview

Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attackers to modify administrator configuration by tricking a logged-in administrator into submitting a forged POST request to the admin.php config update handler, which never invokes the application's CSRF validation function. Attackers can disable the PFS module's file extension whitelist by setting pfsfilecheck to 0, enabling any user with PFS access to upload and execute arbitrary PHP files on the server.

## Affected

- `Cotonti <= 0.9.26`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
