CVE-2026-22194: GestSup <= 3.2.60 CSRF Allows Privileged Actions
GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authenticity of client requests. An attacker can induce a logged-in user to submit crafted requests that perform actions with the victim's privileges. This can be exploited to create privileged accounts by targeting the administrative user creation endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22194?
CVE-2026-22194 has a medium severity level due to the potential for unauthorized actions by an attacker through CSRF.
How do I fix CVE-2026-22194?
To fix CVE-2026-22194, upgrade GestSup to version 3.2.57 or later, which includes patched CSRF vulnerabilities.
Who is affected by CVE-2026-22194?
CVE-2026-22194 affects users of GestSup versions up to and including 3.2.56.
What type of vulnerability is CVE-2026-22194?
CVE-2026-22194 is classified as a cross-site request forgery (CSRF) vulnerability.
What actions can be taken through the exploit of CVE-2026-22194?
An attacker can execute unauthorized actions on behalf of a logged-in user, potentially compromising sensitive operations.