CVE-2026-92751

CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft hidden forms that submit to destructive endpoints like topic deletion and cluster configuration changes, leveraging the operator's HTTP Basic authentication credentials or play-basic-authentication cookie without SameSite protection.
Configurations

No configuration.

History

17 Sep 2026, 15:16

Type Values Removed Values Added
References () https://github.com/yahoo/CMAK/issues/935 - () https://github.com/yahoo/CMAK/issues/935 -

16 Sep 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 21:17

Updated : 2026-09-17 15:16


NVD link : CVE-2026-92751

Mitre link : CVE-2026-92751

CVE.ORG link : CVE-2026-92751


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)