CVE-2026-104059: Lektor 3.3.14 CSRF via Admin API Endpoints

Published Oct 1, 2026
·
Updated

Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a malicious web page to write arbitrary files, delete pages, wipe build output, trigger deployment publication, and via DNS rebinding reach read endpoints to disclose data.

Affected Software

1 affected component
Lektor Lektor=3.3.14, =3.4.0b15

Event History

Oct 1, 2026
CVE Published
via MITRE·06:17 PM
Data Sourced
via MITRE·06:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Lektor versions 3.3.14 and 3.4.0b15 are identified as affected. Exposure requires a victim to access a malicious web page while the Lektor admin API is reachable from the victim's browser.

2

What does an attacker need to exploit the vulnerability?

No authentication is required by the attacker, but exploitation requires user interaction: a victim must load a malicious cross-origin page. The issue is enabled by the absence of CSRF tokens, Origin/Referer validation, CORS configuration, and Host allowlisting on the affected admin API endpoints.

3

What actions can be performed through the vulnerable endpoints?

An attacker can target newattachment, deleterecord, build, clean, and publish to write arbitrary files, delete pages, remove build output, or trigger publication. DNS rebinding can also be used to reach read endpoints and disclose data.

4

How can administrators determine whether they are affected?

Check whether the deployment runs Lektor 3.3.14 or 3.4.0b15 and exposes the admin API to browsers. Review whether the admin API accepts cross-origin state-changing requests without CSRF protections or Origin/Referer validation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203