CVE-2026-82468 - Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type
CVE ID :CVE-2026-82468
Published : Aug. 29, 2026, 5:17 p.m. | 1 hour, 12 minutes ago
Description :Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 29, 2026, 5:17 p.m. | 1 hour, 12 minutes ago
Description :Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...