Description
CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft hidden forms that submit to destructive endpoints like topic deletion and cluster configuration changes, leveraging the operator's HTTP Basic authentication credentials or play-basic-authentication cookie without SameSite protection.
Published: 2026-09-16
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized state changes via CSRF
Action: Immediate Patch
AI Analysis

Impact

CMAK versions up to 3.0.0.6 fail to install a cross-site request forgery filter, allowing attackers to perform state‑changing actions on behalf of authenticated operators. An attacker can craft a hidden form that submits to destructive endpoints such as topic deletion or cluster reconfiguration, using the operator’s HTTP Basic authentication credentials or session cookie without SameSite protection.

Affected Systems

The vulnerability affects Yahoo’s CMAK product version 3.0.0.6 and earlier releases. Deployments of these versions that expose the administrative UI to the internet are susceptible to exploitation.

Risk and Exploitability

The CVSS score is 7.2, indicating that the vulnerability carries a high severity level. However, the EPSS score of less than 1% suggests that the likelihood of active exploitation is currently low and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires a victim to be authenticated (via Basic auth or a cookie) and relies on a cross‑site request to be submitted by a malicious site. If these conditions are met, an attacker can carry out destructive operations without the victim’s knowledge.

Generated by OpenCVE AI on September 17, 2026 at 21:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CMAK to a version that includes the CSRF filter, such as the latest release.
  • If upgrading immediately is not possible, apply a server‑side CSRF filter or require a valid CSRF token for all state‑changing requests.
  • Restrict access to the CMAK administrative endpoints to a trusted network segment and ensure that session cookies use the SameSite attribute or are protected by HTTP Basic authentication that is not transmitted across domains.

Generated by OpenCVE AI on September 17, 2026 at 21:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Yahoo
Yahoo cmak
Vendors & Products Yahoo
Yahoo cmak

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft hidden forms that submit to destructive endpoints like topic deletion and cluster configuration changes, leveraging the operator's HTTP Basic authentication credentials or play-basic-authentication cookie without SameSite protection.
Title CMAK through 3.0.0.6 Cross-Site Request Forgery via Missing CSRF Filter
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:00:14.019Z

Reserved: 2026-09-16T18:57:08.142Z

Link: CVE-2026-92751

cve-icon Vulnrichment

Updated: 2026-09-17T15:00:10.383Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:23.863

Modified: 2026-09-23T17:17:48.170

Link: CVE-2026-92751

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:11:38Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)