CVE-2026-18780: CSRF in TMT Machine's Talassoft Industrial Management Software
Published Sep 1, 2026
·Updated
Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery.
This issue affects Talassoft Industrial Management Software: from V.4 before V.16.
Affected Software
1 affected component
Talassoft Industrial Management Software>4<=16
Event History
Sep 1, 2026
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Talassoft Industrial Management Software versions from V.4 before V.16 are affected.
2
What does an attacker need to exploit this issue?
The CVSS vector indicates network reachability, low attack complexity, no attacker privileges, and required user interaction. Exploitation involves causing a user to interact with a forged cross-site request.