THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-73847 (MEDIUM 6.8) — Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently logged-

[NVD] CVE-2026-73847 (MEDIUM 6.8) — Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently logged-

lownvdPublished 2026-08-14

CVE-2026-73847 CVSS: 6.8 MEDIUM Published: 2026-08-14T18:19:09.843

Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently logged-in administrator. The authentication cookie set in i

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73847