CVE-2026-86182: diem-project diem dmConsole actions.class.php executeCommand cross-site request forgery
A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmConsole. This manipulation of the argument dmcommand causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What access or interaction is needed to exploit this issue?
The attack can be initiated remotely and requires no attacker privileges, but it requires user interaction. The vulnerable request manipulates the dm_command argument used by dmConsole's executeCommand function.
Which deployments are known to be affected?
diem-project diem versions up to 5.1.3 are reported as affected. The available information identifies the dmConsole component, specifically dmAdminPlugin/modules/dmConsole/actions/actions.class.php.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.
Is a vendor fix available?
No vendor response or fix is identified in the provided information. The project was informed through an issue report but had not responded at the time of publication.