CVE-2026-69082: Cross-Site Request Forgery in the Administrative User Deletion Endpoint
CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. The /account/delete/<id> endpoint accepted HTTP GET requests for an operation that modified application state.
An unauthenticated remote attacker could construct a malicious link or embed a request targeting this endpoint and induce an authenticated CTI-Transmute administrator to visit the attacker-controlled content. If the administrator had an active session, the browser would automatically include the administrator’s session credentials, causing the selected user account to be deleted without the administrator intentionally confirming the operation.
Successful exploitation requires interaction from a currently authenticated administrator who has permission to delete users. The attacker does not need a CTI-Transmute account or administrative privileges because the forged request executes using the victim administrator’s session.
The vulnerability could allow an attacker to delete arbitrary user accounts, resulting in unauthorized modification of application state and denial of access for affected users. Depending on whether administrators can delete other administrators or the final administrative account, exploitation could also disrupt administration of the CTI-Transmute instance.
The patch resolves the issue by restricting the deletion endpoint to HTTP POST requests and submitting the deletion through a form containing a CSRF token.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Restrict the /account/delete/<id> deletion operation to HTTP POST requests and require deletion to be submitted via an HTML form that includes a CSRF token (do not allow state-changing behavior via HTTP GET).
CTI-Transmute (administrative user deletion endpoint /account/delete/<id>) HTTP method and CSRF protection = Accept only HTTP POST with CSRF token form submission; reject HTTP GET for state-changing deletion
Event History
Frequently Asked Questions
What is the severity of CVE-2026-69082?
The severity of CVE-2026-69082 is rated as 45, indicating a moderate risk.
How do I fix CVE-2026-69082?
To fix CVE-2026-69082, ensure that the /account/delete/<id> endpoint only accepts HTTP POST requests and implements proper CSRF protection mechanisms.
What type of vulnerability is CVE-2026-69082?
CVE-2026-69082 is a Cross-Site Request Forgery (CSRF) vulnerability.
Can CVE-2026-69082 allow unauthorized access?
Yes, CVE-2026-69082 allows unauthenticated remote attackers to exploit the vulnerability to delete user accounts.
Which software is affected by CVE-2026-69082?
CVE-2026-69082 affects the CTI-Transmute software.