Junglewise Threat Intelligence

CVE-2026-28761: Fujitsu Musetheque V4 CSRF in IPKNOWLEDGE Information Disclosure

CVE-2026-28761 · Severity: high · CVSS 8.1 · Published 2026-05-15

Executive brief

Fujitsu Musetheque V4, a component of the IPKNOWLEDGE information management system, is vulnerable to an attack that can force logged-in users to perform unintended actions. If an authenticated user visits a malicious website, an attacker can hijack their session to modify data or disclose sensitive information without their consent. This could lead to unauthorized administrative changes or the exposure of confidential organizational records.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability (CWE-352) exists in Fujitsu Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. The application fails to properly validate that requests are intentionally initiated by the user, allowing a remote attacker to craft a malicious webpage that triggers unauthorized actions when visited by an authenticated user. Successful exploitation can lead to high impacts on confidentiality and integrity, as the attacker can perform 'unexpected operations' within the context of the victim's session. The vulnerability is addressed in version V4L1 rev2603.1.

Affected products

  • Fujitsu Japan Limited Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier

Timeline

  • 2026-05-15: disclosed
  • 2026-05-15: advisory
  • 2026-05-15: patched: Fixed in V4L1 rev2603.1

References

Related threats