MEDIUM
Cotonti through 1.0.0 Cross-Site Request Forgery via User Group Deletion
Published Sep 28, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.12%
Description
Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft malicious links or pages that trick authenticated administrators into deleting custom groups and their associated permissions by riding the administrator's session.
Affected products
-
- Version 0StatusaffectedConstraints<=1.0.0
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88561 Advisory
- https://github.com/Cotonti/Cotonti product
- https://github.com/Cotonti/Cotonti/blob/1.0.0/system/admin/admin.users.php#L136-L140 technical-description
- https://github.com/Cotonti/Cotonti/issues/1907#issuecomment-5845691148 issue-tracking
- https://github.com/Cotonti/Cotonti/pull/1908 issue-trackingpatch
- https://www.vulncheck.com/advisories/cotonti-through-1.0.0-cross-site-request-forgery-via-user-group-deletion third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88561 | Advisory | |
| https://github.com/Cotonti/Cotonti | product | |
| https://github.com/Cotonti/Cotonti/blob/1.0.0/system/admin/admin.users.php#L136-L140 | technical-description | |
| https://github.com/Cotonti/Cotonti/issues/1907#issuecomment-5845691148 | issue-tracking | |
| https://github.com/Cotonti/Cotonti/pull/1908 | issue-trackingpatch | |
| https://www.vulncheck.com/advisories/cotonti-through-1.0.0-cross-site-request-forgery-via-user-group-deletion | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 28, 2026
Updated Sep 29, 2026
Reserved Sep 27, 2026
Link CVE-2026-101093
CISA Vulnrichment
Updated Sep 29, 2026
ENISA EUVD
EUVD-2026-88561 Assigner VulnCheck
Published Sep 28, 2026
Updated Sep 29, 2026
Exploited since n/a
Link EUVD-2026-88561