CVE-2026-92751: CMAK through 3.0.0.6 Cross-Site Request Forgery via Missing CSRF Filter

Published Sep 16, 2026
·
Updated

CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft hidden forms that submit to destructive endpoints like topic deletion and cluster configuration changes, leveraging the operator's HTTP Basic authentication credentials or play-basic-authentication cookie without SameSite protection.

Affected Software

1 affected component
CMAK<=3.0.0.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade CMAK to a version that resolves this vulnerability.

    Fixed in 3.0.0.6Patch Cross-Site Request Forgery via Missing CSRF Filter

Event History

Sep 16, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Authenticated CMAK operators are exposed if they use HTTP Basic authentication or a play-basic-authentication cookie that lacks SameSite protection. An attacker can cause actions to be submitted in the operator's authenticated browser session.

2

What does an attacker need to exploit it?

The attacker does not need CMAK credentials, but must induce an authenticated operator to interact with attacker-controlled content, such as a page containing a hidden form. The form can submit requests to state-changing CMAK endpoints.

3

What actions could be performed through exploitation?

The provided information identifies destructive actions including topic deletion and cluster configuration changes. These actions are performed with the permissions of the authenticated operator whose session is used.

4

Which CMAK versions are known to be affected?

CMAK through version 3.0.0.6 is affected. The supplied data does not identify a fixed version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203