CVE-2026-82468

Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-29 17:17

Updated : 2026-09-11 18:26


NVD link : CVE-2026-82468

Mitre link : CVE-2026-82468

CVE.ORG link : CVE-2026-82468


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)