Vulnerability Description
Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin functions allows attackers to trick authenticated administrators into performing unauthorized actions like system registration, plugin management, and configuration changes. This issue has been patched in version 2.6.11.
Related Weaknesses (CWE)
References
- https://github.com/emlog/emlog/security/advisories/GHSA-cqqp-rx28-gv2q
- https://github.com/emlog/emlog/security/advisories/GHSA-cqqp-rx28-gv2q
FAQ
What is CVE-2026-42286?
CVE-2026-42286 is a documented vulnerability. Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin functions allows attackers to trick authenticated administrators into performing una...
How severe is CVE-2026-42286?
CVSS scoring is not yet available for CVE-2026-42286. Check NVD for updates.
Is there a patch for CVE-2026-42286?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.