Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-29 17:17
Updated : 2026-09-11 18:26
NVD link : CVE-2026-82468
Mitre link : CVE-2026-82468
CVE.ORG link : CVE-2026-82468
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
