Vulnerability Description
basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as creating an Alertmanager silence or requesting a Prometheus reload. The final impact depends on the APIs enabled by the upstream services.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://gist.github.com/Zykis1024/cec690012eecac53f408e78d2b569f06
- https://github.com/basecamp/upright
- https://github.com/basecamp/upright/blob/efe4f2e5254ac6e57e45d2261804cca74dbbca3
- https://github.com/basecamp/upright/blob/efe4f2e5254ac6e57e45d2261804cca74dbbca3
FAQ
What is CVE-2026-67990?
CVE-2026-67990 is a vulnerability with a CVSS score of 5.4 (MEDIUM). basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logge...
How severe is CVE-2026-67990?
CVE-2026-67990 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-67990?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.