CVE-2026-92751High· 8.1▾ MidnightPoC availableCMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft hidden forms that submit to destructive endpoints l…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 44.6 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
Exploit / PoC code exists
0.2%
CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft hidden forms that submit to destructive endpoints like topic deletion and cluster configuration changes, leveraging the operator's HTTP Basic authentication credentials or play-basic-authentication cookie without SameSite protection.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92778Medium· 5.4CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate
CVE-2019-13529High· 8.8An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior
CVE-2026-63373Medium· 4.2draw.io is a configurable diagramming and whiteboarding application
CVE-2026-54510High· 7.1Speakr is a personal, self-hosted web application designed for transcribing audio recordings
CVE-2026-59148High· 8.8Mockoon provides way to design and run mock APIs
CVE-2026-86281Medium· 4.3A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0