THREAT OPS › Threat News › [NVD] CVE-2026-73847 (MEDIUM 6.8) — Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently logged-
[NVD] CVE-2026-73847 (MEDIUM 6.8) — Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently logged-
CVE-2026-73847 CVSS: 6.8 MEDIUM Published: 2026-08-14T18:19:09.843
Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently logged-in administrator. The authentication cookie set in i
Indicators of compromise
- CVE-2026-73847cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73847