CVE-2026-86307: light0011 cms cross-site request forgery
A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attack can be initiated remotely and requires user interaction. Because this is a cross-site request forgery issue, exploitation depends on inducing a user to perform a request in their existing browser session.
Are fixed or affected versions available?
No affected or updated version details are available because the product uses a rolling-release model. The identified code revisions are c774dce31c6df0055568a8d5c53d964d99be199d and f72cf46f601efb2a0618c3814cc2f61380b38930.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.
Has the project addressed the report?
The project was notified early through an issue report, but no response has been reported.