CVE-2026-100524
Last modified
CVE-2026-100524 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attackers to perform state-changing actions without anti-CSRF token validation. Attackers can craft links or embed images to force administrators to install, update, pause, or unpause extensions by tricking them into visiting a malicious page while authenticated..
Description
Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attackers to perform state-changing actions without anti-CSRF token validation. Attackers can craft links or embed images to force administrators to install, update, pause, or unpause extensions by tricking them into visiting a malicious page while authenticated.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-100524?
How severe is CVE-2026-100524?
How do I fix CVE-2026-100524?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10051In Eclipse Jetty, a first HTTP/1.1 request with trailers cau…7.5
- CVE-2026-10052A flaw was found in the Quay config-tool's LDAP and SMTP val…4.1
- CVE-2026-100520Laranode versions before 1.2.1 contain a path traversal vuln…8.8
- CVE-2026-100521Cotonti through 1.0.0 contains a reflected cross-site script…6.1
- CVE-2026-100522Cotonti through 1.0.0 contains a reflected cross-site script…6.1
- CVE-2026-100523Cotonti through 1.0.0 contains an open redirect vulnerabilit…6.1
- CVE-2026-10053GitLab has remediated an issue in GitLab CE/EE affecting all…8.8
- CVE-2026-10054In affected versions of Eclipse Theia (1.8.1 and later), the…8.8
- CVE-2026-10055In Eclipse Theia since version 1.26.0, the backend /services…8.5
- CVE-2026-10056CORS misconfiguration in the REST API of Network Optix Nx Wi…7.5
- CVE-2026-10057ITS Intelligent SCADA System developed by ITP Technology has…4.8
- CVE-2026-10058ITS Intelligent SCADA System developed by ITP Technology has…4.8
Are you affected by CVE-2026-100524?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
