CVE-2026-1835
Last modified
CVE-2026-1835 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A vulnerability was identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. This affects an unknown part. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
A vulnerability was identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. This affects an unknown part. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-1835?
How severe is CVE-2026-1835?
How do I fix CVE-2026-1835?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18344The Wp Responsive Thumbnail Slider plugin for WordPress is v…6.1
- CVE-2026-18345The WP User Manager plugin for WordPress is vulnerable to un…4.3
- CVE-2026-18346The TikTok plugin for WordPress is vulnerable to authorizati…5.3
- CVE-2026-18347The Kirki – Freeform Page Builder, Website Builder & Customi…4.3
- CVE-2026-18348Missing authorization check in the upload_azure, upload_sftp…4.1
- CVE-2026-18349Improper protection against voltage and clock glitches vulne…7.3
- CVE-2026-18351The Drag and Drop File Upload for Elementor Forms plugin for…9.8
- CVE-2026-18352The User Access Manager plugin for WordPress is vulnerable t…7.5
- CVE-2026-18353PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT a…8.8
- CVE-2026-18355A heap buffer overflow flaw was found in the SASL I/O layer …7.5
- CVE-2026-18356The Limit Login Attempts Reloaded WordPress plugin before 3.…3.7
- CVE-2026-18357The WPC Order Tip for WooCommerce WordPress plugin before 3.…7.5
Are you affected by CVE-2026-1835?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
