Junglewise Threat Intelligence

CVE-2026-86307: light0011 CMS cross-site request forgery

CVE-2026-86307 · Severity: medium · CVSS 4.3 · Published 2026-09-07

Technologies: Light0011 CMS.

Executive brief

light0011 CMS is a content management system used for news publishing and user interaction features. A cross-site request forgery (CSRF) vulnerability in administrative endpoints allows an attacker to trick logged-in administrators into performing destructive actions such as deleting users, navigation items, and polls, or changing comment and poll settings without their knowledge or consent.

Technical details

The vulnerability is a cross-site request forgery (CSRF) flaw affecting multiple administrative state-changing endpoints in the application. The root cause is the lack of anti-CSRF token validation and insufficient HTTP method restrictions; several destructive actions are exposed as GET requests (e.g., Manager/delete, Nav/delete, Vote/delete, Vote/first), and POST endpoints similarly accept requests without CSRF protection. An attacker can exploit this by hosting malicious HTML on a different origin that, when loaded by an authenticated administrator, triggers state-changing requests using the victim's session cookie. The attack requires the target user to be logged in with administrative privileges but does not require additional user interaction beyond visiting a malicious page. There is no indication of an available patch; the project maintainer was notified through a GitHub issue but has not responded.

Affected products

  • light0011 CMS commit f72cf46f601efb2a0618c3814cc2f61380b38930 and earlier; rolling release

Timeline

  • 2026-07-18: disclosed: GitHub issue #12 opened by ThanatosXingYu
  • 2026-09-07: advisory: CVE-2026-86307 published

References