basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as creating an Alertmanager silence or requesting a Prometheus reload. The final impact depends on the APIs enabled by the upstream services.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-13 14:17
Updated : 2026-09-08 19:42
NVD link : CVE-2026-67990
Mitre link : CVE-2026-67990
CVE.ORG link : CVE-2026-67990
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
