Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 29 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts. | |
| Title | Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type | |
| Weaknesses | CWE-352 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T16:35:30.408Z
Reserved: 2026-08-29T14:11:07.433Z
Link: CVE-2026-82468
No data.
Status : Received
Published: 2026-08-29T17:17:59.213
Modified: 2026-08-29T17:17:59.213
Link: CVE-2026-82468
No data.
OpenCVE Enrichment
Updated: 2026-08-29T18:00:12Z
Weaknesses