Vulnerability Description
Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/jeremyevans/rodauth
- https://github.com/jeremyevans/rodauth/commit/3e0d7ab2d49a5733d1afcaaf1062b8a825
- https://github.com/jeremyevans/rodauth/security/advisories/GHSA-hh2f-xw94-5p79
- https://www.vulncheck.com/advisories/rodauth-before-2.47.0-csrf-protection-bypas
FAQ
What is CVE-2026-82468?
CVE-2026-82468 is a vulnerability with a CVSS score of 4.7 (MEDIUM). Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types ...
How severe is CVE-2026-82468?
CVE-2026-82468 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-82468?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.