CVE-2026-67993: Basecamp Upright vulnerability
Published Sep 29, 2026
·Updated
basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback.
Affected Software
1 affected component
Basecamp Upright=efe4f2e5254ac6e57e45d2261804cca74dbbca3f
Event History
Sep 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
Description
Frequently Asked Questions
1
Which component should be reviewed for exposure?
Review the static credentials callback in Upright's sessions controller. The issue is identified in the source tree at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f.
2
What kind of attack does this enable?
The issue is a login cross-site request forgery condition. An attacker could cause a victim's browser to submit a login request through the affected static credentials callback.